Verticalmove, Inc · 1 month ago
Senior & Lead Application Security Engineer
Verticalmove, Inc is a pioneer in Scientific Data Cloud, focused on redefining how life sciences harness data. They are seeking a hands-on Product Security Technical Lead to drive the design, implementation, and evolution of their security engineering program, ensuring the security of their SaaS and data platforms.
Human ResourcesProject ManagementStaffing Agency
Responsibilities
Own and evolve the organization’s entire application security posture, with a focus on application and cloud security across all product lines
Perform offensive and defensive security assessments — threat modeling, code review, penetration testing, and vulnerability exploitation
Build and integrate automated security tooling (SAST, DAST, dependency scanning, IaC scanning) into CI/CD pipelines
Develop security automation and internal tooling using Python, Bash, or Go
Partner with Engineering, DevOps, and Infrastructure teams to ensure secure AWS architectures (VPC, IAM, KMS, GuardDuty, CloudTrail, WAF)
Oversee incident response and root cause analysis for product and infrastructure-level security events
Define and enforce secure coding standards, and lead threat modeling sessions for critical features and services
Continuously hunt for vulnerabilities, test assumptions, and “break things safely” to strengthen the platform
Qualification
Required
8+ years of hands-on experience in Application, Cloud, or Product Security roles, with lead or staff-level responsibilities
Deep expertise in AWS security architecture and service hardening
Advanced programming and scripting ability in Python (Bash or Go a plus)
Proven experience with offensive security: hacking, exploit analysis, or red team operations
Strong foundation in vulnerability management, threat modeling, and incident response
Proficient with DevSecOps tools and modern CI/CD environments
Familiarity with container and orchestration security (Docker, Kubernetes, EKS)
Bachelor's degree in computer science or another equivalent degree
Preferred
Certifications such as AWS Certified Security – Specialty, OSCP, or CISSP
Experience in SaaS, Big Data, or high-scale distributed environments
Knowledge of MITRE ATT&CK, OWASP Top 10, and secure software design principles