10 days ago

Sr. Security Engineer

Aha!

Hybrid
Full Time
$160,000
Hybrid

Job Overview

Job TitleSr. Security Engineer
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$160,000
LocationHybrid

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Aha!

Aha! is the world's #1 product development software. We help more than 1 million product builders to bring their strategy to life. Our integrated tools empower teams to go from discovery to delivery. The suite includes Aha! Roadmaps, Aha! Discovery, Aha! Ideas, Aha! Whiteboards, Aha! Builder, Aha! Develop, Aha! Teamwork, and Aha! Knowledge. Product teams rely on our expertise, AI assistant, and training programs via Aha! Academy to do their best work. We are proud to be a very different type of high-growth SaaS company. The business is self-funded, profitable, and 100% remote. We are recognized as one of the best fully remote companies to work for, champion the Bootstrap Movement, and have given over $1.5M to people in need through Aha! Cares. Learn more at www.aha.io.

Our Engineering Team

The Aha! engineering team is a midsized, fully remote group that is highly productive. We are centered around North American time zones so we can collaborate during the workday.

  • We help each other grow: We each bring unique skills to the table and want our teammates to feel valued from the start. Our onboarding program exposes new hires to the codebase and lets them contribute right away.
  • We move quickly: We ship code multiple times a day. We believe in getting valuable features in front of customers and iteratively improving as we learn what works and what does not.
  • We value product over process: We want the team to have the time and focus needed to solve complex challenges. We minimize overhead by setting clear goals and avoiding heavyweight processes and excessive meetings.
  • We share knowledge freely: We share our learnings with one another and with the developer community. Our engineering blog demonstrates how we tackle interesting challenges at Aha!
  • We enjoy: We like what we do. And we want you to love your team and your job too. Learn more about The Responsive Method, our company values, and the generous benefits we offer.

Our Technology Stack

Our web application is a single-instance, multitenant Ruby on Rails monolith supported by Postgres (database), Redis (background jobs), Kafka (event processing), and Memcached (Rails caching). We also run a Node.js webserver to support collaborative editing and real-time updates. Our application is hosted on Amazon Web Services and architected with ECS for reproducibility and scalability.

We use a growing amount of React on the front end to build rich client-side experiences, including our fully collaborative text editor and slide presentation editor. We balance the strengths of both technologies: Rails for its conventions and simplicity and React for more powerful interactive functionality.

Teammates embrace the new technologies that help us deliver a lovable product suite, but we also remain cognizant of the maintenance overhead a new library or platform brings. We solve the problems in front of us — rather than prematurely optimizing to address issues that might never materialize.

We do most of our planning and collaboration in Aha! Roadmaps and built Aha! Develop so software engineers and their teams can take advantage of those same rich features. We use Slack and Zoom for video calls. (Email? Rarely.)

Your Role as a Sr. Security Engineer

The primary focus of this role is web application security, so you should be deeply knowledgeable about vulnerabilities and mitigations. You are familiar with securing data in multitenant architectures and have helped engineers build secure applications.

Required Experience & Skills

We believe that being a kind person who elevates the rest of the team is just as valuable as writing great code. You are humble, eager to learn, and always willing to help others. You want teammates who enjoy solving problems, regardless of the technologies and techniques involved. You have worked at meaningful scale before and want to do so again. You also have the following experience and skills:

  • Four+ years of experience working in application security
  • Active collaborator with engineering and product teams
  • Experience with security reviews or threat modeling for a full-stack web application
  • Experience with security tools such as CodeQL or Burp Suite
  • Experience with Ruby on Rails is a plus

What You'll Do at Aha!

The security team works across our suite of products and provides guidance for the larger engineering team across the full stack. We are passionate about data security and helping each other. As a Sr. Security Engineer, your work will include:

  • Identifying application security threats and mitigations early
  • Improving and maintaining security code scanning tools
  • Contributing to application security scanning or testing
  • Developing and sharing secure patterns internally for ongoing education

If the Sr. Security Engineer role sounds appealing, we would love to hear from you. (A real human reviews every application.)

Growth & Benefits

Everyone deserves to reach their fullest potential. We know that when we do work that matters with people we care about in a high-growth environment, we feel engaged and alive. It is why we joined Aha! and how we achieve our very best.

We offer all the benefits you would expect and more, including profit sharing. The specific benefits listed below are reflective of what we offer U.S.-based hires. We also do our best to extend identical benefits to international teammates.

  • The base salary range for this role in the U.S. is between $110,000 and $190,000
  • Cash-based compensation also includes profit sharing, and we contribute a percentage of your total pay each month toward your retirement
  • Medical, dental, and vision plans (for many teammates, we cover 100% of the premiums)
  • Up to 200 hours of paid time off a year to spend however you want
  • 30 to 90 days of paid parental leave and five to 10 days of paid care and bereavement leave
  • Up to $1,000 annually for third-party education, along with paid time off to immerse yourself in learning
  • Volunteer opportunities throughout the year

Base salary and total compensation are dependent upon many factors, including skills, experience, and relevant past roles.

Key skills/competency

  • Application Security
  • Web Security
  • Threat Modeling
  • Security Reviews
  • Code Scanning
  • Vulnerability Management
  • Ruby on Rails
  • PostgreSQL
  • AWS Security
  • Multitenant Architecture

Tags:

Senior Security Engineer
Application security
Web security
Threat modeling
Vulnerability management
Code scanning
Security reviews
Data security
Mitigations
Secure patterns
Security testing
Ruby on Rails
Postgres
Redis
Kafka
Memcached
Node.js
React
AWS
ECS
CodeQL
Burp Suite

Share Job:

How to Get Hired at Aha!

  • Research Aha!'s culture: Study their mission, values, "Responsive Method," and remote work philosophy on their website.
  • Tailor your resume: Highlight application security, Ruby on Rails (if applicable), and multitenant architecture experience prominently.
  • Showcase security expertise: Emphasize experience with web vulnerabilities, threat modeling, and tools like CodeQL or Burp Suite.
  • Demonstrate collaborative spirit: Prepare examples of cross-functional teamwork with engineering and product teams.
  • Understand their tech stack: Familiarize yourself with Ruby on Rails, Postgres, Redis, Kafka, and AWS for relevant discussions.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background