Application Security Engineer - remote
Hey there stranger π You can continue to read or listen to Anna tell you a summary here :) (https://share.synthesia.io/0f01245e-0412-4949-bbdb-1cad91d5f60f)
TL:DR
π¬ We are making the future and changing everything we think we know about video production
π The role is remote in Europe or on-site from our offices (London, Copenhagen, Munich, Amsterdam)
π©βπ» We are looking for our 1st dedicated Application Security Engineer
πΆ 90-130k EUR/GDP gross yearly + stock options
π¦ We finished last year with a 50 million β¬ Series B investment, and 70% of our clients are B2B, including a lot of Fortune 500 enterprises. We have a very high NPS of 71 and customer reviews of 4.8/5 on G2.
β¬ Below, you find much more info and the apply button β
Who are we
On a mission to make video easy for anyone β¦
Synthesia is the worldβs #1 AI video generation platform. Well, itβs actually a video production studio β in a browser. As in, no cameras or film crews at all. You simply choose an avatar, enter your script in one of 60 languages, and your video is ready in minutes. In Synthesia, you can build personalised on-the-fly videos, give your chatbot a human face or run 24/7 weather channels in different languages, to name just a few of the possibilities. π¬
We believe the future of media is synthetic, and we are on a mission to turn cameras into code and make everyone a creator. Not sure what weβre talking about? Check out our brand video that explains what weβre doing at Synthesia in a way that even our grandparents *kind of * understand what this AI video stuff is all about.
About the position
We are looking to onboard our first dedicated Security Engineer! You will be part of the Security department, and will report to the Head of Security - while working very closely with our product development team.
We are seeking a highly motivated individual with a strong blue team focus to join us. As a key member of our product security program, you will be responsible for helping to establish and maintain a secure environment for our products. You will be hands-on in solving security issues. We are not looking for internal pentesters. In other words, we want someone who removes work for the dev teams, not someone who creates more work.
Responsibilities include building a scalable security presence within development teams by establishing an Application Security Champions program, facilitating the integration of security tools with the development pipeline, making them self-service for engineering teams, running and scaling security activities such as threat modeling, code scanning, web app scanning, threat detection, and architectural and code reviews. Additionally, you will provide subject matter expertise on topics such as secure design, security controls, programming practices, encryption, and web security standards. You will lead vulnerability management and exposure assessments when vulnerabilities are discovered and ideally, even fix vulnerabilities yourself. You will also implement or assist in the implementation of security-related product features.
Requirements
- You have a passion for security engineering and you want to share this passion with as many like-minded colleagues as possible. You have worked for 2-3 years in an Information Security team, or you have championed security within engineering teams, you a proponent of DevSecOps and you want to deal with interesting problems.
We would expect you to have experience in:
- Web application security principles and have worked hands-on with the OWASP Top 10, the OWASP ASVS or the CWE Top 25
- Working with a Secure Development Lifecycle model (e.g. OpenSAMM, BSIMM)
- Software development (we use Python and TypeScript, running on Docker)
- Working with vulnerability assessment / management tools (e.g. Wiz, Snyk, SynAck)
- Working within the context of an Information Security framework (e.g. ISO 27001, SOC 2, PCI DSS)
- Working with security in the cloud (we are on AWS)
- Working with Github
Bonus points for:
- Any relevant Information Security certification, e.g AWS Certified Security, GIAC GWEB, OSCP, or CSSLP.
- A university degree in Computer Science, IT, Systems Engineering, or a similar field.
The good stuff...
πΈ You will be compensated well (salary + stock options + bonus)
π You will work in a remote-first environment with offices in 5 locations
π You get 25 days of annual leave + public holidays in the country where you are based
π₯³ You will join an established company culture with regular socials and company retreats
π€© You get 4 weeks paid sabbatical after 4 years at the company + $10,000!!
πΌ You get a paid parental leave
π You can participate in a generous referral scheme
π You will have huge opportunities for your career growth
Apply for this job
Other AI Jobs like this
Director of Treasury
OpenAI
Copyright Counsel
Anthropic