Skip to main content
ThorneTH

Senior DevSecOps / Security Engineer – Application & Cloud (Ecommerce)

Thorne is a health technology company founded in 1984 that develops clinically tested, science-backed nutritional supplements and personalized wellness solutions to help individuals live healthier, longer.

Thorne

Employee count: 201-500

Salary: $150K – $180K per year

CA, DK + 8 more

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

At Thorne, we work to deliver high-quality, science-backed solutions to empower individuals to take a proactive approach to their well-being. Each day begins with a mission to help others discover and achieve their best health. We count on our team members to challenge and push the boundaries to make that happen. At Thorne, you’ll be joining a team of more than 750 passionate individuals committed to our cause of providing superior health solutions at every age and life stage.Thorne is seeking a Senior DevSecOps / Security Engineer – Application & Cloud (Ecommerce) to secure and scale our digital platforms, including Thorne.com, mobile applications, and emerging AI capabilities. This role sits at the intersection of application security, DevSecOps, and AWS cloud infrastructure, with a strong focus on protecting ecommerce systems, customer data, and high-traffic web applications. The ideal candidate will balance remediations and hands-on execution, ensuring systems are resilient, performant, and secure, while embedding security throughout the development lifecycle.

RESPONSIBILITIES


Application & Ecommerce Security
· Identify and remediate vulnerabilities in Java-based applications (Spring Boot, APIs, microservices)
· Address OWASP Top 10 and ecommerce-specific risks, including:
o Injection (SQL/NoSQL), XSS, CSRF

o Broken authentication / session management

o Business logic flaws (checkout, pricing, promotions, abuse scenarios)

o Account takeover, credential stuffing, bot attacks

· Secure checkout flows, payment integrations, subscriptions, and customer data handling

· Conduct secure code reviews and support threat modeling for new features

API & Integration Security

· Secure REST/GraphQL APIs (authentication, authorization, rate limiting)

· Prevent API abuse, scraping, and data exfiltration

· Implement and enforce secure patterns (OAuth2, JWT, token management)

DevSecOps & CI/CD Security

· Implement and manage security tooling in CI/CD pipelines:

o SAST (Java-focused), DAST, SCA (dependencies), secrets scanning

· Secure build and deployment pipelines

· Enforce secure coding standards and automate policy checks

· Own infrastructure-as-code security (Terraform) for app environments

AWS Cloud Security (Critical)

· Secure application workloads on AWS (EKS/ECS, EC2, Lambda, API Gateway, S3, RDS)

· Implement and validate:

o IAM roles and least privilege access

o Network segmentation (VPCs, security groups, private/public boundaries)

o Secrets management (AWS Secrets Manager, Parameter Store)

o Data protection (encryption at rest/in transit)

· Partner with Infra to ensure alignment with enterprise guardrails, while owning app-layer cloud security

Runtime Protection & Detection

· Implement and tune WAF, bot protection, and rate limiting for ecommerce surfaces

· Partner with Infra on CrowdStrike coverage for application workloads

· Support detection and response improvements for:

o Web/app-layer attacks

o API abuse

· Triage and remediate findings from:

o Pen tests

o Purple team exercises

o Assumed breach scenarios

Security Program Execution

· Translate security findings into prioritized engineering work

· Partner with external security testing partners on risk prioritization (CTRM) tied to business impact

· Drive adoption of security best practices across engineering teams

· Act as a bridge between Ecom, Infrastructure, and external security partners

WHAT YOU NEED


Application & Ecommerce Security
· Identify and remediate vulnerabilities in Java-based applications (Spring Boot, APIs, microservices)
· Address OWASP Top 10 and ecommerce-specific risks, including:
  • Injection (SQL/NoSQL), XSS, CSRF
  • Broken authentication / session management
  • Business logic flaws (checkout, pricing, promotions, abuse scenarios)
  • Account takeover, credential stuffing, bot attacks
· Secure checkout flows, payment integrations, subscriptions, and customer data handling
· Conduct secure code reviews and support threat modeling for new features

API & Integration Security
· Secure REST/GraphQL APIs (authentication, authorization, rate limiting)
· Prevent API abuse, scraping, and data exfiltration
· Implement and enforce secure patterns (OAuth2, JWT, token management)
DevSecOps & CI/CD Security
· Implement and manage security tooling in CI/CD pipelines:
  • SAST (Java-focused), DAST, SCA (dependencies), secrets scanning
· Secure build and deployment pipelines
· Enforce secure coding standards and automate policy checks
· Own infrastructure-as-code security (Terraform) for app environments
AWS Cloud Security (Critical)
· Secure application workloads on AWS (EKS/ECS, EC2, Lambda, API Gateway, S3, RDS)
· Implement and validate:
  • IAM roles and least privilege access
  • Network segmentation (VPCs, security groups, private/public boundaries)
  • Secrets management (AWS Secrets Manager, Parameter Store)
  • Data protection (encryption at rest/in transit)
· Partner with Infra to ensure alignment with enterprise guardrails, while owning app-layer cloud security
Runtime Protection & Detection
· Implement and tune WAF, bot protection, and rate limiting for ecommerce surfaces
· Partner with Infra on CrowdStrike coverage for application workloads
· Support detection and response improvements for:
  • Web/app-layer attacks
  • API abuse
· Triage and remediate findings from:
  • Pen tests
  • Purple team exercises
  • Assumed breach scenarios
Security Program Execution
· Translate security findings into prioritized engineering work
· Partner with external security testing partners on risk prioritization (CTRM) tied to business impact
· Drive adoption of security best practices across engineering teams
· Act as a bridge between Ecom, Infrastructure, and external security partners

WHAT WE OFFER

  • Competitive compensation
  • 100% company-paid medical, dental, and vision insurance coverage for employees
  • Company-paid short- and long-term disability insurance
  • Company- paid life insurance
  • 401k plan with employer matching contributions up to 4%
  • Gym membership reimbursement
  • Monthly allowance of Thorne supplements
  • Paid time off, volunteer time off and holiday leave
  • Training, professional development, and career growth opportunities

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: $150K – $180K per year

Hiring timezones

United States +/- 0 hours, and 9 other timezones

About Thorne

Learn more about Thorne and their company culture.

View company profile

We're a health technology company on a mission to help people live healthier, longer. Since 1984, we've been creating science-backed supplements and health solutions based on the belief that personalized wellness can extend your healthspan and create happier, healthier lives. Our team in Summerville, South Carolina manufactures everything right here in the USA, putting every product through four rounds of testing before it ever reaches you.

What sets us apart is our commitment to doing things properly - no shortcuts, no unnecessary fillers, just clean formulations that actually work. We partner with researchers and conduct clinical trials to back up what we make. Our facility is NSF-certified, we're recognized by Australia's TGA (the toughest regulatory agency out there), and we're trusted by organizations like the Mayo Clinic. We've even built Taia, our AI wellness advisor, to help you find the right products for your specific health goals because we know everyone's journey is different.

Claim this profileThorne logoTH

Thorne

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

Remote companies like Thorne

Find your next opportunity by exploring profiles of companies that are similar to Thorne. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan