Aha! logo

Sr Security Engineer

Aha!

Job description

Aha! engineering is a mid-sized, fully remote team. We are centered around North American time zones so we can collaborate during the workday.

Our core values


  • The Responsive Method: These 8 principles drive how we operate Aha! and serve customers and employees.
  • Moving quickly: We ship code multiple times a day. We believe in getting new features in front of customers and iteratively improving as we learn what works and what does not.
  • Product over process: We want our engineers to have the time and focus to solve complex challenges. We aim to minimize the overhead introduced by heavyweight processes and excessive meetings.
  • Collaboration: We each bring unique experiences and skills to the table. Working together to share that knowledge benefits the entire team and helps us produce the best results for our customers.

Who we're looking for


We believe that being a kind person who elevates the rest of the team is just as valuable as writing great code. We look for strong problem-solving skills and experience working on important functionality for a cloud-based product. We need people who are humble, eager to learn, and always willing to help others learn as well. We want to work with people who enjoy picking up a problem and solving it, regardless of the technologies and techniques involved.

The Aha! security team is part of the engineering team and is product focused. As a Senior Security Engineer, you can expect to spend the majority of your time working with Ruby on Rails and JavaScript code for security reviews, investigations, updates, and implementing security features.

Our technology


Our sole product is the Aha! web application. It is a single-instance, multi-tenant Ruby on Rails monolith supported by Postgres (database), Redis (background jobs), and memcached (Rails caching). We also run a Node.js webserver to support collaborative editing and real-time updates. Our application is hosted on Amazon Web Services and architected with ECS for reproducibility and scalability.

We use React for rich client-side experiences on the front end. Some of the features we have built with React include:

  • Our fully collaborative text editor: Supports multiple cursors and simultaneous editing by any number of users. We also published a blog post explaining the underlying technology.
  • Our presentation editor: Allows users to create presentations with slide themes, shapes, text, and embedded Aha! reports (which update live so the presentation is always current).
  • Our Gantt chart: Supports scaling and scrolling to change the timeline, drag-and-drop, and quick actions to create records or sort the bars.

We embrace new technologies that help us deliver a lovable product, but we also remain cognizant of the maintenance overhead that a new library or platform brings. We solve the problems in front of us, rather than prematurely optimizing to address issues that may never materialize.

We do most of our collaboration and planning in Aha! itself, which we find especially rewarding. We also utilize GitHub, Slack, and GoToMeeting for video calls.

What you’ll be doing


We maintain security controls and perform security reviews on a broad range of features across the full stack. Your work will include:
  • Security code reviews that go above and beyond what can be found through scanning tools (which we use too!)
  • Cloud and network security reviews of Amazon Web Services infrastructure that is implemented via infrastructure as code
  • Monitoring third-party dependency vulnerability reports and applying fixes and mitigations
  • Sharing security findings and new developments internally for ongoing education
  • Participating in security monitoring, incident response, and investigations

If this sounds appealing, we would love to hear from you. A real human reviews every application, so please use the form to help us learn more about you.

Apply now

Apply Apply

Please let Aha! know you found this job on Himalayas. This will help us grow!

About this role

Apply before

May 16th, 2021

Job posted on

September 24th, 2020

Job type

Full Time

Hiring timezones

Aha! is hiring for this role in the following timezones:

Badge UTC -10.0
Badge UTC -9.5
Badge UTC -9.0
Badge UTC -8.0
Badge UTC -7.0
Badge UTC -6.0
Badge UTC -5.0
Badge UTC -4.0
Badge UTC -3.5
Badge UTC -3.0
Badge UTC -2.0
Badge UTC +14.0
Primary industry
Company size

51-200

Founded in

2013

Social media
Visit aha.io Visit aha.io

About the company

Aha! is the world's #1 roadmap software. We help more than 5,000 companies and 300,000 users create strategic plans.  The company was founded in 2013 by Silicon Valley veterans and product management ...
View company profile View company profile

We'll keep you updated when the best new remote jobs pop up.

mail
Subscribe

We care about the protection of your data. Read our Privacy Policy.

Featured remote companies

View all companies View all companies
  • Casa logo

    Casa is the secure home for your Bitcoin. One of the greatest promises of Bitcoin is the ability to give people back control of their own money - to "be their own bank".

    Employees

    11-50

  • Gistia Healthcare logo

    We are on a mission to transform the future of healthcare.

    Employees

    11-50

  • Brivity logo

    Our mission at Brivity is to empower agents with the ultimate platform that will guarantee their success in the real estate industry.

    Employees

    11-50

  • Bayes Holding logo

    Bayes Holding (formerly Dojo Madness) is a non-operative holding company specialized in gaming and esports data, offering market-leading tools and services to business customers.

    Employees

    11-50

  • Outbank logo

    What is characteristic about Outbank? We are a team of experts from all over the world.

    Employees

    11-50

  • Vortala logo

    Vortala’s mission is to help healthcare practices attract and retain more new patients using the Internet. Established in 2005, Vortala has grown to be one of the world’s leading healthcare digita

    Employees

    11-50