At Anaplan, we are looking for a self-motivated Senior Security Engineer to join our growing team at Anaplan HQ in the city-by-the-bay, SAN FRANCISCO to be a member of the Security Engineering Team. This is an opportunity for you to work for one of the coolest hyper-growth companies in technology.
As a Senior Security Engineer with a strong DevOps and Cloud mentality, you will help drive the Product Security Architecture & Research function(s) for Anaplan engineering teams. You will also be responsible for working with the other Engineers, Architects, and Security teams across Anaplan, collectively providing mentorship and strategies that improve the security posture for our employees and data. You will be working with business customers, Engineering management, infrastructure, development, project managers, and other security teams to craft the vision, structure, standards, and plan for solutions that support Anaplan’s strategic business direction.
You’ll join a team of individuals who accept and respect diverse perspectives, aren’t afraid to push boundaries and try new ideas, and are passionate about helping our customers and each other succeed. We work hard, but we also don’t wait for an excuse to have fun. In fact, we’re so serious about it that it’s one of our core values!
As a Senior Security Engineer on the Security Engineering Team, you will closely work with Development and Operations to scale the Anaplan Platform. This exciting career with a company that values diversity and invests in you, is at your fingertips!
Located in SOMA district, when you walk into our San Francisco office, you can feel the excitement and energy of what we are doing at Anaplan. Open floor plan, stocked kitchens, and collaboration spaces, we gear our office around making sure you have everything you need to work well. And whether it’s a company outing to a Giants game or team happy hour, there are always events for you to connect with your colleagues outside of work. You will join a team of individuals who accept and respect diverse perspectives, aren’t afraid to push boundaries and try new ideas, and are passionate about helping our customers and each other succeed. We work hard, but we also don’t wait for an excuse to have fun, and we encourage each other!
This role is an immediate full-time position. If you’re ready to roll up your sleeves and seek outstanding problems that no one is solving in the tech space yet, keep reading.
What you’ll be doing:
- Conceive of and collaborate on novel ideas to identify risks at scale.
- Rapidly prototype to assess the efficiency of project ideas.
- Build tools/scripts to find AppSec risks at scale.
- Stay on top of ground breaking AppSec standard methodologies, tools, etc., and assess their utility at Anaplan.
- Understand new technologies and their strengths/weaknesses in the context of AppSec tooling.
- Perform operational security reviews of feature implementations
- Perform regular secure coding & secure design workshops for developers
- Perform risk assessments of new and emerging threat types
- Interface with QA teams by implementing automated security unit and functional tests
More about you:
- Bachelor’s degree in Computer Science, Engineering or a related subject area preferred, and substantial commercial experience in a similar role.
- Prior experience in building pragmatic and effective security testing techniques/tools is a big plus.
- Experience in threat modeling web applications and microservices.
- Strong understanding of Modern Auth (SAML 2.0, OAuth)
- Strong understanding of SSL certificate management, PKI, CA and their use.
- Deep knowledge of web protocols and standards.
- Experience in containers and their hardening/security
- A clear understanding of security concepts e.g., Authentication, Authorization.
- Deep knowledge of application security vulnerabilities (OWASP Top 10) and mitigation techniques.
- Knowledge of emerging threats, mitigations, and industry trends.
- Experience with SAST, DAST tools
- Prior experience in AWS, GCP services, and architectures
- Experience with AWS is a huge plus
Technologies you would work with:
- Kubernetes
- Docker
- Spring Boot
- Projects from Cloud Native Ecosystem
Bonus points:
- Kubernetes
- Jenkins Pipelines