← See other Job Openings at Zapier

Senior Application Security Engineer

Hi there!

We're looking for someone to join our Engineering team at Zapier as an Application Security Engineer Are you interested in helping build and secure a powerful automation tool? Then read on…

We know applying for and taking on a new job at any company requires a leap of faith. We want you to feel comfortable and excited to apply at Zapier. To help share a bit more about life at Zapier, here are a few resources in addition to the job description that can give you an inside look at what life is like at Zapier. We hope you'll take the leap of faith and apply.

Zapier is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

 

About You

You have web application security experience. Keeping the core Zapier web application secure is at the heart of this role. Zapier is a SaaS product, so experience building and securing software under a similar model is a plus.

You have used frameworks to build security into an organization. Using industry standards will give you a head-start, that's why we are looking for familiarity with security development frameworks like MS SDL, OpenSAMM, OWASP ASVS, or BSIMM.

You know what makes browsers and sites secure. The web browser is practically the operating system of the internet; these days, nearly everything that happens online, happens in a browser. You’ll help us continue to keep customer data safe by ensuring the “first mile” is trouble-free.

You know how security mechanisms work. We're looking for knowledge of techniques, standards, and state of the art capabilities for authentication (JWT, OpenID, SAML2.0) and authorization (OAuth 2.0).

You know how to implement a security testing toolchain. One of our core values is "Don't be the robot, build the robot" so we are big on security testing automation (SAST, DAST, SCA, IAST).

You have worked with teams on large Python, AWS, & Kubernetes projects. You’re also familiar with some common frameworks for languages like Django, Flask, or Rails as well as React/Backbone.js. You've also worked extensively in cloud providers like AWS.

You love doing things efficiently. At Zapier, the work you do will have an impact on the business. We believe in systems and processes that let us scale our impact to be larger than ourselves. You'll be in a unique position to find and eliminate "insecure and painful" experiences and replace them with "secure and joyful" experiences.

You love learning. Engineering is an ever-evolving world. You enjoy playing with new tech and exploring areas that you might not have experience with yet.

You love to set your own direction. We have one team meeting and one-on-ones each week. We also like to hang out on video for a few minutes every day to chat with one another. Between those, we chat in Slack and then go make things happen.

You are friendly and patient, welcoming, considerate, and respectful. Learn more about these attributes in our code of conduct.

 

Things You Might Do

Zapier is a small, fast-growing, and remote-first company, so you'll likely get experience on many different projects across the organization. That said, here are some things you'll probably do:

  • Establishing, fine-tuning and monitoring our Security Development Lifecycle
  • Growing our Security Champion Program
  • Implementing new ways to make it harder to introduce security bugs, through automation, security tooling, and reviews
  • Implement security best practices
  • Identify where we can add more layers of defense in depth and implement them
  • Periodically embed within product teams to help with security-sensitive projects
  • Build internal tooling to ensure safe data access patterns for Zapier employees
  • Review code and design across Zapier's product and infrastructure.
  • Locating weak points across Zapier and strengthening them.
  • Experiment: this is a startup so everything can change

As part of our All Hands Support initiative, help customers have the best experience with Zapier as possible.

 

How To Apply

We have a non-standard application process. To jump-start the process we ask a few questions we normally would ask at the start of an interview. This helps speed up the process and lets us get to know you a bit better right out of the gate.

After you apply, you are going to hear back from us, even if we don't seem like a good fit. In fact, throughout the process, we strive to make sure you never go more than seven days without hearing from us.

 

About Zapier

For the past eight years, Zapier has been helping people across the world automate the boring and tedious parts of their job. We do that by helping everyone connect the web applications they already use and love.

We believe that there are jobs a computer is best at doing and that there are jobs a human is best at doing. We want to empower businesses to create processes and systems that let computers do what they are best at doing and let humans do what they are best at doing.

We believe that with the right tools, you can have big impact with less hassle.

We believe in small teams. Small teams are fast and nimble. Small teams mean less bureaucracy and less management and more getting things done.

We believe in a safe, welcoming, and inclusive environment. All teammates at Zapier agree to a code of conduct.

 

The Whole Package

We're currently hiring for the following locations:

  • Europe
  • North America

Compensation:

  • Competitive salary (we don't use remote as an excuse to pay less)
  • Great healthcare + dental + vision coverage*
  • Retirement plan with 4% company match*
  • Profit sharing
  • 2 annual company retreats to awesome places
  • 14 weeks paid leave for new parents of biological or adopted children
  • Pick your own equipment. We'll set you up with whatever Apple laptop + monitor combo you want plus any software you need.
  • Unlimited vacation policy. Plus we require you to take at least 2 weeks off each year. We see most employees take 4-5 weeks off per year. This isn't a vague policy where unlimited vacation means no vacation.
  • Work with awesome companies around the world. We partner with great software companies all over the world and you'll constantly get to interact with people from these great companies

*While we take care of our international folks as best we can, currently, healthcare and retirement plans are only available to US-based employees.

Optional: Share anonymously some demographic information about yourself to help us better track trends related to the backgrounds of candidates interested in working at Zapier in order for us to build a team that represents the users at Zapier and the broader world population.

Zapier is an equal opportunity employer. We're excited to work with talented and empathetic people no matter their race, color, gender, sexual orientation, religion, national origin, physical or mental disability, or age. Our code of conduct provides a beacon for the kind of company we strive to be, and we celebrate our differences because those differences are what allow us to make a product that serves a global user base.

Apply Here