Job Closed

This listing is no longer active.

iHerb, LLC logo
iHerb, LLC

Come join the movement....we are a vehicle to healthy living!

Application Security Lead

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 1,001-5,000Since 1996H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

167 days ago

Salary

$176.5K - $264.8K / year

Seniority

Senior

Bachelor Degree8 yrs expEnglishJavaJavaScriptMicroservicesNode.jsPython.NET

Job Description

Application Security Lead

iHerb, LLC

• Lead cross-functional, enterprise-wide projects and define the strategic direction for cutting-edge security development lifecycle (SDL) practices • Conduct security design reviews and sophisticated threat modeling for new and existing mission-critical services • Establish secure architecture standards, frameworks, and resilient security patterns • Evaluate, prototype, implement, operate, and provide governance over core security tools and services • Discover and analyze emerging security threats • Maintain a strong knowledge of current security threats • Drive security assessment, penetration testing, and bug bounty programs • Ensure all application security practices adhere to PCI DSS requirements • Participate in security incident response activities as a technical leader

Job Requirements

  • Demonstrated technical foundation (Computer Science / Engineering degree or equivalent experience)
  • 8+ years of technical security experience at a top-tier software company
  • Hands-on experience with threat modeling, security design, security architecture, cryptography, mobile security, cloud computing technologies, and security products
  • Expert understanding of common application and infrastructure security vulnerabilities and mitigations (OWASP Top 10, CWE 25…)
  • Deep, demonstrable knowledge of the e-commerce transaction lifecycle
  • Proven track record of driving the implementation of SDL processes, technology, and automation in sophisticated DevOps/DevSecOps environments.
  • Experience with large-scale web applications and microservices
  • Knowledge of major programming languages and frameworks (e.g. Python, C# .NET, JavaScript, node.js, Java...)

Benefits

  • Health insurance
  • 401(k) matching
  • Time Off
  • Paid Sick Leave
  • Paid holidays
  • Eligible for Restrict Stock Units and receive annual bonuses

Related Categories

Related Job Pages

More Security Engineer Jobs

Modern Health logo

Staff Security Engineer

Modern Health

Offering global, personalized mental health care designed to help you feel more resilient, productive, and empowered.

Security Engineer167 days ago
OtherRemoteTeam 201-500Since 2017H1B No Sponsor

• Define and drive the strategic roadmap for proactive security vulnerability analysis in web and mobile applications, setting the organizational standard for risk determination and leading complex, company-wide remediations. • Establish the technical vision and program for integrating robust security controls at every stage of the Software Development Life Cycle (SDLC), championing secure development practices and scalable agile delivery. • Architect, deploy, and manage defensive security tooling (e.g., SAST, DAST, SCA) and evaluate new industry-leading application security solutions to create a robust, automated security platform. • Lead the maturation of the Product and Application Security Program by developing and implementing security policies, standards, and metrics to continually raise the security bar and demonstrate compliance. • Lead collaborative and cross-functional threat modeling initiatives for core systems, new features, and evolving services, ensuring proactive risk identification and structural security improvement. • Engage with Cloud Security efforts by partnering with DevOps and Infrastructure teams to assess, improve, and monitor cloud architecture, security policies, and cloud-native controls to ensure secure deployment and operations.

United States
$160.7K - $189K / year
Job Closed
Upwind Security logo

Customer Success Manager

Upwind Security

Cloud Security Happens at Runtime.

Security Engineer167 days ago
OtherRemoteTeam 51-200H1B No Sponsor

• Own the strategic relationship with assigned strategic customers • Drive business value and ensure long-term retention and growth • Serve as the primary business-facing contact and trusted advisor for customers • Own the post-sale customer journey from onboarding through renewal • Collaborate with Sales on long-term account strategy • Partner closely with TAMs to drive adoption of new capabilities • Develop and manage joint success plans aligned to customer objectives • Build strong relationships across executive, security, DevOps, and cloud leadership • Lead Quarterly Business Reviews (QBRs) and program reviews

California
OtherRemoteTeam 11-50Since 2023H1B No Sponsor

• Own product roadmap, priorities, and execution • Translate cybersecurity workflows into clear product requirements • Work closely with Engineering, AI/ML, and Security Research teams • Define MVPs, iterate fast, and ship production-ready features • Gather feedback from customers, pilots, and internal stakeholders • Balance security depth, usability, and business goals • Contribute to product positioning and go-to-market alignment

United States
Job Closed
Environmental Management Authority logo

Software Engineer – Product Security

Environmental Management Authority

The Environmental Management Authority is committed to protecting and conserving the natural environment to enhance life

Security Engineer168 days ago
Full TimeRemoteTeam 51-200H1B No Sponsor

• Design, build, and maintain internal security tools and platforms to improve Ema’s overall security posture. • Implement and improve security controls directly into product and platform workflows. • Influence engineering architecture and ensure secure-by-design implementations. • Own and scale application security programs including SAST, SCA, dependency risk, and custom detection logic. • Support penetration testing efforts by validating findings and engineering durable fixes. • Perform threat modeling for new features and systems, translating risks into concrete engineering solutions. • Develop automation to reduce manual security effort across vulnerability management, access reviews, and incident response. • Conduct secure design and code reviews with a strong focus on exploitable logic flaws and systemic risks. • Build tooling to surface security signals from production systems and dev workflows.

India
Job Closed