Application Security Architect

Sorry, this job was removed at 9:44 a.m. (PST) on Monday, March 2, 2020
Find out who's hiring remotely in Greater LA Area.
See all Remote Cybersecurity + IT jobs in Greater LA Area
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

We’re looking for an Application Security Architect ready to play a ground floor role in developing application security tooling and processes within all phases of the Software Development Life Cycle (SDLC).  In this role, you will work closely with product engineering teams to define application security standards, instrument security testing, support vulnerability triage, participate in identification of risk across our platform and will advocate for security in all aspects of our product.  Our clients entrust FloQast with their financial data and as such it is our mission to deliver features that provide resilience, confidence and trust in our platform. We believe in scaling security through software engineering best practices and automation. You'll play a fundamental role in shaping the future of security at FloQast and your work will have significant impact and visibility.

What you’ll do…

  • Participate in architecture design reviews with senior engineering and product management staff to incorporate effective threat modeling and security standards into product design.
  • Educate team members on application security coding standards and best practices, and work to establish a regular training program.
  • Develop processes and automation for security reviews and testing activities including those within the CI/CD pipelines, and evaluate application security tools to improve our detection and prevention capabilities.
  • Explain and demonstrate vulnerabilities to application/system owners, and provide recommendations for mitigation.
  • Build process by which discovered vulnerabilities can be quickly triaged, tracked and remediated by product engineering teams.
  • Work with product owners to inform and prioritize product security engineering roadmaps and facilitate secure development of in-product functionality that allows product teams independent access to sensitive data sets in a secure and compliant manner.
  • Participate in strategic activities to evangelize security objectives and ensure their appropriate consideration in product and operational planning across all teams.
  • Advise senior management on perceived risks and work to determine an acceptable risk appetite while weighing overall business and usability impact.  
  • Advise and communicate security priorities, controls, technologies and pertinent policies to all relevant stakeholders and team leads.
  • Stay current with new and emerging security technologies and paradigms.  Makes recommendations for their use based on business value.

We’re looking for someone with...

  • 6+ years of experience in web or mobile application security role.
  • 5+ years building or working with distributed multi-tier web server-client architectures.
  • Working knowledge of the Microsoft Security Development Lifecycle (SDL), OWASP Software Assurance Maturity Model (SAMM), or Building Security in Maturity Model (BSIMM).
  • Experience conducting secure code development training.
  • Experience implementing security practices in automated CI/CD pipelines for application code, infrastructure, and/or serverless is a plus.
  • Experience performing secure design review and threat modeling in order to assess the security implications and requirements of new systems and technologies.
  • Strong foundational understanding of network and application fundamentals and best practices e.g. HTTP/S, DNS, VPN, Load Balancing, SAML, OAuth, OpenID etc.
  • Strong understanding of OWASP Top 10 vulnerabilities in web applications including XSS, SSRF, IDOR, RCE, CSRF vulnerabilities.
  • Strong understanding of AWS offerings (e.g. VPC, ELB/ALB, ECS, EC2, SQS, SNS, Lambda, etc.) or equivalent cloud infrastructure provider offerings.
  • Experience utilizing web application security scanning software and penetration testing tools e.g. Burp Suite, ZAP, Metasploit, NMAP, CANVAS, Cobalt Strike, Empire etc.
  • Strong sense of ownership, urgency and drive.
  • Strong ability to lead cross-team initiatives and communicate proposals and ideas concisely.

Nice to have attributes…

  • Experience securing multi-tenant enterprise SaaS products.
  • Knowledge of common compliance frameworks a plus e.g. SOC, SOX, PCI and ISO standards.
  • Security Certifications e.g. CISSP, CISM, CEH, AWS Certified Solutions Architect, AWS Certified Speciality.

About FloQast    www.floqast.com

FloQast is a fast-growing, Los Angeles-based, growth-stage company redefining how a critical business process (financial close) is performed.  Our growth and success are fueled by a passion to define and dominate the close management software market. We are the first company of our kind to focus specifically on the mid-market. Our prospects have been hungry for a solution like FloQast and the response has made FloQast among the fastest growing FinTech companies with now more than 750 customers, including Lyft, Zoom, Twilio and the Golden State Warriors.

- We are fanatics about the success of our customers.  Check us out on G2 Crowd 

- We are equally fanatic about creating and maintaining a fabulous culture of support and success for all employees.  

- We are moving quickly and there is a huge upside opportunity in terms of career growth

- FloQast offers competitive compensation, stock options, full benefits, and a positive and supportive work environment   

- Named among Best Places to Work by LA Business Journal in 2017, 2018 and 2019

- Ranked #10 on The SaaS 1000  

FloQast, Inc is committed to operating fair and unbiased recruitment procedures allowing all applicants an equal opportunity for employment, free from discrimination on the basis of religion, race, sex, age, sexual orientation, disability, color, ethnic or national origin, or any other classification as may be protected by applicable law. We aim to recruit the right people for the jobs we have to offer, and to assess applications on the basis of relevant skills, education, and experience. We welcome people of different backgrounds, experiences, abilities and perspectives. We are an equal opportunity employer and strive to provide a professional and welcoming workplace for all employees.

 

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are FloQast Perks + Benefits

FloQast Benefits Overview

FloQast offers a range of employee benefits including: competitive compensation, stock options, 100% employer paid Medical, Dental, Vision plans for employees and their families, Group Life Insurance, Short Term and Long Term Disability, Flexible Spending Account, unlimited vacation, fun social events. access to free online therapy and a positive and supportive work environment.

Culture
Volunteer in local community
FloQast partners with Big Brothers Big Sisters of LA for a mentorship program with local at-risk high school youth. We invite our employees to volunteer as "Bigs" in the program.
Partners with nonprofits
FloQast has partnered with Holiday Heroes, a Chicago based charity, to launch the Los Angeles chapter. Holiday Heroes partners with local hospitals to provide parties for terminally ill children.
Open door policy
OKR operational model
Team based strategic planning
Pair programming
Open office floor plan
Flexible work schedule
Remote work program
FloQast's Employee Choice policy allows employees to choose to be hybrid or remote!
Diversity
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Our recruiting team offers an unconscious bias training for all employees who participate in the interview process to help make the candidate experience fair.
Mean gender pay gap below 10%
Diversity employee resource groups
FloQast has 5 Employee Resource Groups (so far!) where our employees can join and build a community with each other and share resources.
Hiring practices that promote diversity
Applicants can submit anonymous demographic data during the application process which HR monitors for a diverse pipeline and to ensure candidates are being treated equitably in each interview stage.
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
A Medical and Dependent Care FSA is offered to all US employees.
Disability insurance
FloQast offers fully paid Short Term and Long Term Disability plans to US employees.
Dental insurance
FloQast pays 100% of Dental Insurance premiums for employees and their families.
Vision insurance
FloQast pays 100% of Vision Insurance premiums for employees and their families and offers a buy-up plan if desired.
Health insurance
FloQast pays 100% of Medical Insurance premiums for employees and their families and offers a buy-up plan if desired.
Life insurance
FloQast offers free Group Life Insurance and the option to purchase more out of pocket if desired.
Pet insurance
FloQast offers a discount on Pet Insurance as well as a plan that offers discounts and savings on vet care, prescriptions and preventative care.
Wellness programs
Team workouts
FloQast provides virtual Yoga to our employees!
Mental health benefits
Free access for all Employees and their dependents to Talkspace, an online therapy platform.
Financial & Retirement
401(K)
Company equity
Performance bonus
Charitable contribution matching
Child Care & Parental Leave Benefits
Childcare benefits
FloQast subsidizes the use of the baby bassinet SNOO for new parents, it helps buy back at least 1 hour of sleep per night with a newborn.
Generous parental leave
FloQast provides 16 paid weeks to birthing parents and 12 weeks paid weeks to non-birthing parents for Parental Leave.
Family medical leave
FloQast follows state and federal law in regards to job protected leave.
Adoption Assistance
FloQast provides 12 weeks paid weeks to non-birthing parents for Parental Leave.
Return-to-work program post parental leave
Company sponsored family events
FloQast hosts virtual events for employees with children ranging from petting zoos to craft classes.
Vacation & Time Off Benefits
Unlimited vacation policy
Generous PTO
Paid volunteer time
FloQast has partnered with Big Brothers Big Sisters of Los Angeles to provide a virtual workplace mentoring program to at-risk youth in the Los Angeles, CA area.
Paid holidays
Paid sick days
Office Perks
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Ample parking is available at our physical locations.
Recreational clubs
Relocation assistance
Fitness stipend
Home-office stipend for remote employees
Remote employees are provided with reimbursement limits to purchase certain office equipment for their at home workspace.
Professional Development Benefits
Job training & conferences
Lunch and learns
FloQast hosts a Quarterly Lunch and Learn where all Department Heads will present on their team initiatives, goals, accomplishments and provide insight into how their input affects company operations.
Promote from within
Continuing education stipend
Paid industry certifications

Additional Perks + Benefits

Competitive compensation; Medical, Dental, Vision 100% employer paid for Employees, Spouse and Dependents!; Group Life, Short Term and Long Term Disability at no cost to Employees; Flexible Spending Account (FSA); Fast growth and opportunity for career growth; Positive and supportive work environment; We're always looking for more ways to enhance employee benefits as we grow as a Company!

More Jobs at FloQast

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about FloQastFind similar jobs like this