LastPass, the #1 password leader, provides password and identity management solutions that are convenient, easy to manage, and effortless to use, helping more than 32 million users and 100,000 businesses organize and protect their online lives. As a pioneer in cloud security technology, LastPass provides award-winning password and identity management solutions that are convenient, effortless, and easy to manage. LastPass values users’ privacy and security, so your sensitive information is always hidden – even from us.

We welcome new ideas, support your growth, and recognize your value, if this aligns with what you are looking for in your next career move, Join Us

 

LastPass is looking for a Senior Application Security Engineer (PHP):

The LastPass Product Security team is seeking a Senior Application Security Engineer (PHP) to join our dynamic team and help us ensure the security of our applications. 

If you are passionate about complex problem solving and motivated by scale, then this is the role for you!

Who will you work with?

As a Senior Application Security Engineer (PHP) in LastPass, you will partner with software engineers, product owners and our architect team to ensure security best practices across our products.

What are some of the exciting challenges you will be working on?

  • Join a passionate application security team committed to enhancing LastPass's product security.
  • Apply your expertise in security architecture to assist software engineers in developing secure products and services from the ground up.
  • Collaborate closely with engineering and platform teams to understand their application security requirements.
  • Conduct application security design reviews, engage in threat modeling, and perform code reviews.
  • Utilize your penetration testing skills to bolster the security of both internal and external applications and services.
  • Address complex server-side application issues written in PHP through debugging and troubleshooting.
  • Educate engineering teams and security champions in secure coding and development practices

What does it take to work at LastPass?

  • Strong written and verbal communication skills in English
  • Extensive technical expertise in web application security
  • Experience in developing and/or securing web applications written in PHP
  • Fundamental understanding of Docker and container security
  • Prior experience with threat modeling, testing, and analyzing server-side applications
  • Proficiency in identifying software flaws and effectively communicating solutions
  • Previous collaboration with engineering teams and support throughout the SDLC (Software Development Life Cycle)
  • Team-oriented, proactive, and adaptable attitude

It’s great, but not required:

  • Experience with .NET
  • Experience with TypeScript and React
  • Experience with GitLab CI/CD
  • Experience with AWS (Amazon Web Services) 

Why LastPass? 

  • Market-leading password manager
  • High-growth, collaborative environment with inclusive teams
  • Remote first culture
  • Competitive compensation 
  • Flexible Paid time off policies including but not limited to: Monthly self-care days (12 extra paid days off annually), volunteering days
  • Generous Parental leave
  • Comprehensive health coverage, dependents included
  • Home office setup support
  • LastPass families free account up to 5 members
  • Continuous learning and development opportunities

 Unlock your potential with us - your skills, experience, and unique perspective matter more than just checking the boxes. Apply today, and let's build the future together!

We’re building an inclusive community that reflects the people of all races, genders, sexual orientations, national origins, backgrounds, and perspectives who share our world.

For all US based jobs please review our  Applicant Privacy Notice

For all EU based jobs please review our Candidate Privacy Notice 

Please review our CCPA Notice

 

Apply for this Job

* Required

resume chosen  
(File types: pdf, doc, docx, txt, rtf)



Our system has flagged this application as potentially being associated with bot traffic. Please turn off any VPNs, clear your browser cache and cookies, or try submitting your application in a different browser. If this issue persists, please reach out to our support team via our help center.
Please complete the reCAPTCHA above.