Sr. Security Engineer
Aha!
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
About Aha!
Aha! is the world's #1 product development software used by over 1 million product builders. Our suite includes tools such as Aha! Roadmaps, Discovery, Ideas, Whiteboards, Builder, Develop, Teamwork, and Knowledge. We are a fully remote, self-funded, profitable, and high-growth SaaS company that values product over process and champions a supportive, collaborative culture.
The Team
The Aha! engineering team is a midsized, fully remote group primarily working in North American time zones. We encourage growth from day one and a culture of learning, quick iteration, minimal bureaucracy, and knowledge sharing.
Technology
The web application is built as a Ruby on Rails monolith, utilizing Postgres, Redis, Kafka, and Memcached. Additional support is provided by a Node.js server for real-time features. Hosting is on Amazon Web Services with ECS for scalability. React is increasingly used for interactive components alongside Rails.
Your Role as Sr. Security Engineer
In this role, you will focus on web application security by identifying threats, improving security scanning tools, and contributing to secure coding practices across our suite of products. Key duties include:
- Identifying application security threats and mitigations early
- Improving and maintaining security code scanning tools
- Contributing to security scanning/testing and secure patterns
- Collaborating with engineering and product teams
Your Experience
Required experience includes 4+ years in application security, experience with threat modeling and security tools (e.g., CodeQL, Burp Suite), and a background in securing full-stack web applications. Experience with Ruby on Rails is a plus. A humble, collaborative spirit is highly valued.
Benefits & Compensation
The role offers a base salary range between $110,000 and $190,000 for U.S.-based hires, profit sharing, comprehensive health plans, generous paid time off, parental leave, education stipends, and volunteer opportunities. Compensation is adjusted based on skills and experience.
Key skills/competency
Security, Web Application, Threat Modeling, Ruby on Rails, CodeQL, Burp Suite, AWS, Remote, Collaboration, SaaS
How to Get Hired at Aha!
- Research Aha!'s culture: Study their remote work values and technology stack.
- Customize your resume: Highlight security and web application experience.
- Prepare examples: Be ready to discuss past threat modeling projects.
- Show collaboration skills: Emphasize teamwork and cross-functional projects.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background