Application Security Engineer
Overview
Corporate Tools is hiring an Security Engineer for $175,000/year. You will be a traditional company employee. This is a remote position, but if you’re near one of our local offices, you’re welcome to come hangout with us in-office as well. Our main offices are in Post Falls, ID, and Spokane, WA; we also have satellite offices in Austin, TX, and Salt Lake City, UT. You’ll be working 40 hours a week and, of course, enjoy great company benefits.
We are expanding our team to include a Security Engineer to be 100% focused on our security efforts. As the right candidate, you will have experience working in-house as a full-time penetration tester, a regular 3rd party bug bounty program pen tester, or in a similar security type role. Your job will be to identify our vulnerabilities to help keep our information safe and secure.
Wage
Benefits
-
100% employer-paid medical, dental & visionFull coverage for employees — nothing comes out of your paycheck. Plus an annual review with a raise option.
-
Time off that grows with you22 days PTO + 4 holidays to start. After 3 years it bumps to 29 days, and after 5 years you move to flexible time off — not accrued, not capped. Take time off when you want.
-
Parental leave & 401(k) matchPaid parental leave, plus up to 6% company 401(k) matching with no vesting period — it’s yours from day one.
-
Quarterly allowanceSpend it on whatever makes work better: a comfier remote setup, continuing-education classes, a plant for your desk, coffee for a coworker, a massage for yourself… really, whatever.
-
No dumb perks (and a trail mix bar)No weekend dog-walking gimmicks that look cool but cost nothing because nobody uses them. We spend on benefits you’ll actually use — an open-concept office, friendly coworkers, a creative environment, and yeah… a trail mix bar.
Responsibilities
Understand and safely use various open source penetration testing tools and when appropriate, emulating hacker tactics, techniques, procedures
Create security vulnerability reports for both technical and executive audiences
While in-between assessments, you will be expected to help our security engineers think through solutions to problems you find
Automate tasks and script at a basic level to enhance penetration testing processes
Passion for learning new technologies and processes, and contributing to refining existing capabilities
Communicate with stakeholders (technical and non-technical), both verbal and written
Stay up to date on 0 day exploits for tech stacks we use
Requirements
Solid fundamentals in webapp and network pentesting (2+ years). Pentesting experience in mobile apps, APIs, and/or cloud environments a bonus
4+ years of professional experience in Ruby on Rails or equivalent and Vue or a Frontend equivalent framework
Experience with Linux and cloud environment testing
Understanding of security issues for desktop, virtual, cloud services and network infrastructures
Working knowledge of information systems security standards/practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling)
Experience with secure network protocols and encryption of communications between networked hosts
Experience in IT systems and security policies, standards, industry trends, and techniques
Experience with assessing APT threats, Penetration Testing, Vulnerability Management, attack methodologies, forensics analysis techniques, malware analysis, attack surface comprehension, Cyber Threat Emulation operations, Cyber Advanced Threat Emulation Team operations and research, identification, and/or verification of new APT TTPs
Fundamental understanding of security knowledge of testing mobile, native applications, web applications, distributed and database systems
Must be detail-oriented and possess strong problem-solving skills and ability to analyze for potential future issues
Solid understanding of common webapp vulnerabilities, exploitation techniques, and remediation options
Why Work Here
You’ve changed a price on a website you were checking out on to see if it worked. You’ve messed around where you shouldn’t have and you’ve always thought it would be fun to do that full time in a way that didn’t make you feel like an evil person or that karma would catch up to you. Maybe you’ve messed with folks in the past too much and want to earn some good karma points by helping us secure our high volume software and systems.
#BI-Remote
