FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Application Security and secure software development practices, with a strong focus on threat modeling, CI/CD pipeline security, and AWS cloud security. Proficient in writing production code in Ruby and PHP, while actively collaborating with Engineering teams to implement security solutions.
Highest-signal resume keywords
Application SecurityThreat ModelingCI/CD Pipeline SecurityRuby ProgrammingAWS Cloud Security
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
RubyGoPHPThreat ModelingSecure-By-Design PrinciplesSASTSCASecret ScanningAWS/LambdaAutomations
Soft Skills
CollaborationCommunication
Tools & Technologies
CI/CD PipelineSecurity Tools
Certifications & Qualifications
Information Security Certifications
Industry Keywords
Application SecurityProduct SecurityGuardrailsToolingSecurity Fixes
Tech Stack
Tools & technologiesAWSGoPHPRuby
About the role
Key responsibilities & impact- Assess technical vulnerabilities and propose solutions to improve the security of our platform, working in our stack (Ruby, Go, and PHP) and developing security fixes on AWS/Lambda.
- Quickly assess development queue demands, reducing the AppSec bottleneck and unblocking Engineering deliveries.
- Actively propose and implement fixes in code, going beyond merely reporting findings.
- Conduct threat modeling and apply secure-by-design principles to product initiatives.
- Create guardrails, tooling, and automations that make the secure path the default for Engineering teams.
- Integrate and tune security tools in the CI/CD pipeline (SAST, SCA, and secret scanning), keeping noise and false positives low.
Requirements
What you’ll need- Experience in software engineering or security, writing and delivering production code (ideally Ruby and PHP), including automations on AWS/Lambda.
- Experience in Application Security/Product Security: threat modeling, secure-by-design, and creating guardrails and tooling.
- Strong knowledge of CI/CD pipeline security, with calibrated SAST, SCA, and secret scanning.
- Knowledge of AWS cloud security as applied to the product.
- Information security certifications are a plus.
- Strong ability to collaborate with Engineering teams, proposing and implementing fixes directly in code — not just reporting findings.
- Ability to communicate in English (written and spoken).
Benefits
Comp & perks- 100% remote work.
- Trust-based culture, results-oriented, with plenty of challenge and learning opportunities.
- Autonomy and ownership in a collaborative and empathetic environment.
- Feedback culture and regular 1:1s with human leadership and no micromanagement.
- Comprehensive benefits including meal/food allowance, childcare assistance, home office stipend, health coverage, education and cultural benefits, Gympass, birthday day-off, discounts on therapy and English courses, among other partnerships.
