Security Software Engineer
Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.
About the job
Responsibilities
- Develop core security services, including permissions management, secrets orchestration, and secure MLOps.
- Build secure-by-default libraries and frameworks for engineering teams.
- Enhance CI/CD pipelines with automated security controls such as SAST and supply-chain security checks.
- Support secure code and architecture reviews and threat modeling.
- Harden cloud infrastructure through network isolation, vulnerability detection, and defense-in-depth strategies.
- Contribute to security incident response, risk documentation, and SOC 2 compliance audits.
- Advise engineering teams on security best practices and reduce developer security friction.
Requirements
- 1–2+ years of hands-on software engineering experience or equivalent practical experience.
- Bachelor’s degree in computer science or a related field, or strong technical fundamentals.
- Proficiency in at least one modern programming language, such as Ruby, TypeScript, Python, or C++.
- Familiarity with web security concepts, modern development practices, and integrating security into the software development lifecycle.
- Strong debugging, maintainable-code, communication, collaboration, and problem-solving skills.
- Willingness to learn new technology stacks.
Nice-to-haves
- Internship or collaborative coding project experience.
- Familiarity with SAST scanners, vulnerability detection tools, or LLM-assisted coding tools.
- Security experience through CTF competitions, open-source contributions, or personal projects.
Compensation and Benefits
- Base salary: $148,000–$183,000 annually.
- Meaningful equity.
- Medical, dental, and vision coverage.
- Unlimited flexible paid time off.
- Paid parental and new child bonding leave.
- Monthly self-care days.
- Wellbeing resources, including fitness classes, mindfulness tools, virtual therapy, and family planning assistance.
- Support for management training, conferences, workshops, and certifications.
Skills
Ruby, TypeScript, Python, C++, Web Security, CI/CD, SAST, Kubernetes, Docker, GCP, Terraform, SCIM, RBAC, MFA, Threat Modeling
Similar jobs
Security Engineering jobsOwn and operate Vertex Synapse, integrating and modeling threat intelligence while delivering it to detections, blocklists, data pipelines, and security workflows. Requires at least two years of production threat-intelligence platform or security data-pipeline experience and software development skills in Python, Go, or Storm.
Build and operate foundational security services spanning identity, access, secrets, privileged access, and secure AI-agent infrastructure. The role requires at least two years of production software engineering experience, cloud expertise, and experience translating security requirements into reliable automated systems.
Security engineer responsible for detection engineering, investigations, incident response, identity and access management, and preventative security controls across corporate and production environments. Requires 2+ years of security engineering experience, programming ability, and familiarity with cloud and defensive security tooling.
Security Engineer focused on application and platform security, security reviews, threat modeling, vulnerability management, and secure development practices. The role requires at least two years of relevant experience, programming ability, and familiarity with cloud security technologies.
Corporate Security Engineer responsible for identity, endpoint, SaaS, and security automation controls across the company. The role requires 2–5 years of security engineering experience, hands-on endpoint and EDR expertise, identity protocol knowledge, and scripting ability.