Mattermost · 6 hours ago
Product Security Engineer (Remote)
Maximize your interview chances
File SharingInformation Services
Insider Connection @Mattermost
Get 3x more responses when you reach out via email instead of LinkedIn.
Responsibilities
Support the application vulnerability management and mitigation approaches
Conduct application security reviews through manual code review or static/dynamic code analysis
Engage in threat modeling and design reviews of in-house developed software components
Provide security guidance and training to internal development teams
Triage SCA findings and support internal development teams in SCA findings remediation
Improve and/or automate existing processes to increase efficiency
Qualification
Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.
Required
Deep understanding of web application security and secure development practices
Deep understanding with common security libraries, security controls, and common security flaws
Experience with Threat Modeling applications
Experience with static/dynamic analysis, and common exploit tools and methods
Experience in one or more programming languages, ideally Go or JavaScript
Excellent written and verbal communication skills
Demonstrable teamwork skills and resourcefulness
Preferred
Experience working in open-source communities
Experience running a bug bounty program
Certifications in the domain of penetration testing or application security (e.g. OSCP, OSWE, GWAPT, …)
Experience with Electron, React or React Native
Participation in Bug Bounties, CTFs or similar activities
Company
Mattermost
Mattermost is an open source platform for secure collaboration across the entire software development lifecycle.
Funding
Current Stage
Growth StageTotal Funding
$73.5MKey Investors
Y CombinatorRedpointS28 Capital
2019-06-19Series B· $50M
2019-02-05Series A· $20M
2017-02-15Seed· $3.5M
Recent News
Company data provided by crunchbase