Sobre esta vaga de Lead Application Security Engineer na Panthalassa
About the Company
We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on capturing civilizational levels of ultra-low-cost renewable energy for applications including computing and affordable renewable fuels delivered to shore.
The company is a public benefit corporation headquartered in Portland, Oregon, and backed by leading venture capitalists, philanthropic investors, university endowments, and private investment offices. We operate as an idea meritocracy in which the best ideas change the company’s direction on a regular basis.
Our staff have worked at organizations such as SpaceX, Blue Origin, Boeing, Tesla, Apple, Virgin Orbit, Astra, Google, Amazon, Microsoft, New Relic, Bridgewater, Raytheon, Disney Imagineering, and the US Army and Air Force, as well as research universities, startups, and small companies across a range of industries.
About the Job
Our core technology is the node, a device that produces energy in the ocean’s harshest conditions for years at a time without human maintenance or intervention.
As a Lead Application Security Engineer, you will play a key role in advancing Panthalassa’s application security capabilities, partnering closely with the Director of Information Security and software engineering teams. You will bring broad application security and software engineering expertise, strong technical judgment, and the ability to quickly understand unfamiliar languages, frameworks, and architectures. Candidates should possess broad application security and software engineering skills, and be able to quickly come up to speed with languages and frameworks with which they have not previously worked.
Candidates should have strong interpersonal skills and be able to thrive in a creative, scrappy, and collaborative environment in which the best ideas change the company’s direction on a regular basis.
Responsibilities
- Assist the Head of Information Security with building out the AppSec function at Panthalassa.
- Conduct code and service architecture reviews to provide security guidance.
- Lead engineers in threat modelling applications and services.
- Work with the Head of Information Security to define culturally useful software security metrics.
- Assist in interviewing and onboarding of other Security personnel.
- Assist with incident response and handling now while we grow, and provide escalation support for incidents later as we have grown.
- Integrate, maintain, and automate security scanning tools (SAST, DAST, SCA, and secrets management) directly into our CI/CD pipelines.
- Build and integrate agentic security tools for Panthalassa needs.
- Conduct hands-on threat modeling and architectural design reviews for new features and applications before code is written.
- Perform manual and automated secure code reviews as well as targeted penetration testing on web and mobile applications.
- Help manage the company’s external Vulnerability Disclosure or Bug Bounty programs and translate regulatory compliance requirements into practical engineering tasks.
Required Qualifications
- 6+ years of experience with Application Security processes.
- 2+ years of experience as a Team Lead or Manager of an Application Security team.
- Both broad in general and deep in places Application Security foundational knowledge.
- Experience with using AI systems and agents for security outcomes in a professional capacity.
- Deep understanding of the OWASP Top 10, CWE Top 25, and secure design patterns.
- Hands-on experience with industry-standard security tools (e.g. Snyk, GitHub Advanced Security, Burp Suite, Fortify).
- Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience.
Desired Qualifications
- Experience with software development work related to mechanical engineering environments.
- Familiarity with cloud platforms (AWS, Azure, or GCP) and modern infrastructure tools like Docker, Kubernetes, and Infrastructure as Code (IaC).
The above qualifications are desired, not required. We encourage you to apply if you are a strong candidate with only some of the desired skills and experience listed.
Additional Requirements
- Travel to conferences, vendors and test sites as needed.
- Intermittently able to work longer hours and weekends to support critical needs. While we expect a lot of each other, we also offer a high degree of autonomy and work-life balance, including flexible PTO and flexible working hours.
Compensation and Benefits
If hired for this full-time role, you will receive:
- Cash compensation of $200,000 - $260,000.
- Equity in the company. We’re all owners and if we’re successful, this equity should be far and away the most valuable component of your compensation.
- A benefits package that helps you take care of yourself and your family, including:
- Flexible paid time off
- Health insurance (the company pays 100% of gold-level PPO plan for full-time employees, their partners, and dependents)
- Dental insurance (the company pays 100% for full-time employees, their partners, and dependents)
- Vision insurance (the company pays 100% for full-time employees, their partners, and dependents)
- Disability insurance (the company pays 100% for a policy to provide long-term financial support if you become disabled)
- Ability to contribute to tax-advantaged accounts, including 401(k), health FSA, and dependent care FSA
- Relocation assistance to facilitate your move to Portland (if needed).
Location
This is an on-site position. Our offices, lab, and shop are located in Portland, Oregon.