Application Security Engineer II - Product Security (Remote)

undefined ago • All levels • Product Management

Job Summary

Job Description

As an Application Security Engineer II on CrowdStrike’s Product Security team, you will protect CrowdStrike and its customers from advanced threats by securing applications. This role focuses on active threats to CrowdStrike’s products, involving digging into web applications, identifying design and implementation flaws, and assisting product engineers in fixing defects to ship secure code. You will act as a security expert and advisor to engineering teams, create threat models, review source code, attack applications throughout the Secure Development LifeCycle, and build automation tools. Additionally, you will assist with the bug bounty program and harden internal systems.
Must have:
  • Join engineering teams as a security expert and advisor
  • Create and maintain threat models to drive security decisions
  • Review application source code for security defects and risk
  • Attack applications throughout the Secure Development LifeCycle
  • Work with developers to help them understand defects and implement solutions
  • Build integrated tools and automation for security tasks
  • Assist in responding to the bug bounty program
  • Moderate understanding of software product creation in Agile/DevOps environments
  • Moderate experience with threat modeling, especially using STRIDE
  • Code review experience for apps built with Go, Python, or Java
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS)
  • Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites
  • Understanding of common software weaknesses that impact cloud and web applications and experience in application penetration testing
  • Comfort with collaborating across technical teams
  • Experience with driving ambiguous research projects
Good to have:
  • Self-motivated to identify security problems and engage with teams
  • Demonstrable experience developing/maintaining automation for application security tasks and defect identification
  • Positive working relationship with product engineers
  • Knowledge of Docker and Kubernetes (k8s)
  • Ability to explain and demonstrate the limitations of AI assisted development and associated security implications
  • Engaged in providing security enhancements to open source projects
  • Experience with threat intelligence driven testing and adversarial emulation
Perks:
  • Remote-friendly and flexible work culture
  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™ across the globe

Job Details

About The Role

Help us protect CrowdStrike and its customers from the most advanced threats by securing our applications. CrowdStrike’s Product Security team breaks the mold of traditional internal security, and focuses on active threats to CrowdStrike’s products. As an Application Security Engineer you will dig into web applications, find design and implementation flaws, help our product engineers fix defects, and play a role in shipping secure code. You’ll hunt for security defects and play a part in fixing those defects rather than just reporting them and hoping for the best. Additionally, you will be involved in cross-cutting projects to further harden internal systems and processes against active and emerging threats.

What You’ll Do:

  • Join engineering teams working on applications as a security expert and advisor, influencing the design and capabilities of our products
  • Create and maintain threat models to drive security decisions and minimize threat surface area
  • Review application source code, looking for security defects and risk
  • Attack applications throughout the Secure Development LifeCycle
  • Work with developers to help them understand defects, risks, design weaknesses, etc. and implement proven solutions
  • Build integrated tools and automation to make life easier for you, your team, and our engineering partners
  • Assist in responding to our bug bounty program, hunt for similar issues, and improve the security of our applications

We’re hiring this role at multiple levels, so we still want to hear from you even if you think you can’t do all of that – or if you can do more!

What You’ll Need:

  • A moderate understanding of how software products are created and shipped in Agile/DevOps like environments
  • Moderate experience with threat modeling, especially using STRIDE
  • Code review experience for apps built with Go (Golang), Python, or Java
  • Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS)
  • Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites
  • An understanding of common software weaknesses that impact cloud and web applications (not just the OWASP Top 10) and experience in application penetration testing
  • Comfort with collaborating across technical teams: asking technical questions, challenging assumptions, getting or providing context for decisions, etc.
  • Experience with driving ambiguous research projects

Bonus Points:

These skills are not required and/or we’re willing to teach them, but they are helpful.

  • Self-motivated to identify security problems and engage with teams to find solutions
  • Demonstrable experience developing/maintaining automation for application security tasks and defect identification
  • Example(s) of having a positive working relationship with product engineers (software product development experience is a huge bonus)
  • Knowledge of Docker and Kubernetes (k8s)
  • Can explain and demonstrate the limitations of AI assisted development and associated security implications
  • Engaged in providing security enhancements to open source projects
  • Experience with threat intelligence driven testing and adversarial emulation

Education/Certifications:

Technical security certifications or academic background are a plus.

#LI-SF1

#LI-MF1

#LI-Remote

#HTF

Benefits of Working at CrowdStrike:

  • Remote-friendly and flexible work culture
  • Market leader in compensation and equity awards
  • Comprehensive physical and mental wellness programs
  • Competitive vacation and holidays for recharge
  • Paid parental and adoption leaves
  • Professional development opportunities for all employees regardless of level or role
  • Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
  • Vibrant office culture with world class amenities
  • Great Place to Work Certified™ across the globe

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in United States

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Product Management Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

CrowdStrike was founded in 2011 to fix a fundamental problem: The sophisticated attacks that were forcing the world’s leading businesses into the headlines could not be solved with existing malware-based defenses. Founder George Kurtz realized that a brand new approach was needed — one that combines the most advanced endpoint protection with expert intelligence to pinpoint the adversaries perpetrating the attacks, not just the malware. There’s much more to the story of how Falcon has redefined endpoint protection but there’s only one thing to remember about CrowdStrike: We stop breaches.
View All Jobs

Get notified when new jobs are added by Crowd Strick

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug