Our mission is to make hourly work easier for local businesses and hourly workers. Homebase currently serves more than 100,000 small (but mighty) businesses with everything they need to manage their hourly teams: employee scheduling, time clocks, payroll, team communication, hiring, onboarding, and compliance. Just don’t call us “Human Capital Management.” We have built tools for the busiest businesses, so owners and employees can spend less time on bullsh*t and more time on what matters. The Homebase team brings small business expertise from Intuit, Square, OpenTable, Yelp, Gusto, and First Data. Homebase is backed by leading venture investors Bain Capital Ventures, Baseline Ventures, Cowboy Ventures, Khosla Ventures, Plus Capital, and GGV Capital.
We’re currently hiring in all Homebase hubs: Atlanta, GA, Houston, TX, Austin, TX, Denver, CO, San Francisco, CA, Los Angeles, CA, and Toronto, CA
As a Security Engineer at Homebase, you will work in a Product Security/Application Security role to improve the security and privacy around Homebase customer data that enables thousands of small businesses to safely and reliably manage their operations. By reviewing upcoming releases, identifying security vulnerabilities, implementing systemic improvements, and working with all teams in the organization to remediate issues. You will play a leading role in protecting the data of our customers and in securing the integrity of our systems.
You’ll balance security with end-user efficiency and business needs
You’ll help other engineers design more secure systems via design input and code review.
You’ll manage our Bug Bounty program, triage incoming reports, and work with the rest of the engineering team to address vulnerabilities.
You’ll be a champion for security across the entire business.
3+ years of experience on an internal application security team or related discipline.
Experience working with web and mobile applications teams
Knowledge of common attacks and exploitation techniques
Knowledge of threat modeling and architecture design review
Knowledge of network and related web protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)
Strong communication skills.
Bachelor's degree in Computer Science or Engineering disciplines or equivalent required
Knowledge of development best practices, both for mobile and web applications.
Knowledge of Git, Github, and development using pull requests.
Knowledge of product incident response.
Development experience in ruby on rails applications.
Experience triaging and working in bug bounty programs
Experience in using standard Security Assessment and Penetration Testing tools such as BurpSuite, Metasploit, and OWASP Zap.
5+ years of experience working on an internal application security team
What We Offer You
Colorado Only: The salary range for this position is $120-$170K per year. Final offers may vary based on several factors including experience and expertise.
Stock Options - everyone is an owner
Comprehensive Insurance Plans
401(k) program +4% company match
Remote, hybrid, and in-office work options
Top-of-the-line equipment and home office $$
Annual Holidays and Accrued PTO
A dynamic, well-connected, productive team
Fun company activities
At Homebase, we value our differences, and we encourage all to apply. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Homebase is proud to be an equal opportunity employer and participant in the U.S. Federal E-Verify program.