RESPONSIBILITIES
Application & Ecommerce Security
o Broken authentication / session management
o Business logic flaws (checkout, pricing, promotions, abuse scenarios)
o Account takeover, credential stuffing, bot attacks
· Secure checkout flows, payment integrations, subscriptions, and customer data handling
· Conduct secure code reviews and support threat modeling for new features
API & Integration Security
· Secure REST/GraphQL APIs (authentication, authorization, rate limiting)
· Prevent API abuse, scraping, and data exfiltration
· Implement and enforce secure patterns (OAuth2, JWT, token management)
DevSecOps & CI/CD Security
· Implement and manage security tooling in CI/CD pipelines:
o SAST (Java-focused), DAST, SCA (dependencies), secrets scanning
· Secure build and deployment pipelines
· Enforce secure coding standards and automate policy checks
· Own infrastructure-as-code security (Terraform) for app environments
AWS Cloud Security (Critical)
· Secure application workloads on AWS (EKS/ECS, EC2, Lambda, API Gateway, S3, RDS)
· Implement and validate:
o IAM roles and least privilege access
o Network segmentation (VPCs, security groups, private/public boundaries)
o Secrets management (AWS Secrets Manager, Parameter Store)
o Data protection (encryption at rest/in transit)
· Partner with Infra to ensure alignment with enterprise guardrails, while owning app-layer cloud security
Runtime Protection & Detection
· Implement and tune WAF, bot protection, and rate limiting for ecommerce surfaces
· Partner with Infra on CrowdStrike coverage for application workloads
· Support detection and response improvements for:
o Web/app-layer attacks
o API abuse
· Triage and remediate findings from:
o Pen tests
o Purple team exercises
o Assumed breach scenarios
Security Program Execution
· Translate security findings into prioritized engineering work
· Partner with external security testing partners on risk prioritization (CTRM) tied to business impact
· Drive adoption of security best practices across engineering teams
· Act as a bridge between Ecom, Infrastructure, and external security partners
WHAT YOU NEED
Application & Ecommerce Security
- Injection (SQL/NoSQL), XSS, CSRF
- Broken authentication / session management
- Business logic flaws (checkout, pricing, promotions, abuse scenarios)
- Account takeover, credential stuffing, bot attacks
API & Integration Security
- SAST (Java-focused), DAST, SCA (dependencies), secrets scanning
- IAM roles and least privilege access
- Network segmentation (VPCs, security groups, private/public boundaries)
- Secrets management (AWS Secrets Manager, Parameter Store)
- Data protection (encryption at rest/in transit)
- Web/app-layer attacks
- API abuse
- Pen tests
- Purple team exercises
- Assumed breach scenarios
WHAT WE OFFER
- Competitive compensation
- 100% company-paid medical, dental, and vision insurance coverage for employees
- Company-paid short- and long-term disability insurance
- Company- paid life insurance
- 401k plan with employer matching contributions up to 4%
- Gym membership reimbursement
- Monthly allowance of Thorne supplements
- Paid time off, volunteer time off and holiday leave
- Training, professional development, and career growth opportunities
