Back to jobs

Application Security Engineer [Remote-US]

To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors looking for personal data. Please be aware we will only reach out via email using the domain quanata.com. Anything that does not match those domains should be ignored and considered a security risk.

About Us

Quanata is on a mission to help ensure a better world through context-based insurance solutions. We are an exceptional, customer centered team with a passion for creating innovative technologies, digital products, and brands. We blend some of the best Silicon Valley talent and cutting-edge thinking with the long-term backing of leading insurer, State Farm.

Learn more about us and our work at quanata.com
 
Our Team
 
From data scientists and actuaries to engineers, designers and marketers, we’re a world class team of tech-minded professionals from some of the best companies in Silicon Valley, and around the world.  We’ve come together to create the context-based insurance solutions and experiences of the future.  We know that the key to our success isn't just about nailing the technology—it’s hiring the talented people who will help us continue to make a quantifiable impact.

The Role

We are seeking an Application Security Engineer to join our Information Security team. This role is pivotal in ensuring the security and integrity of our cloud-based platform and shared solutions within our B2B/E product suite. You will be responsible for implementing application security measures across various projects, with a focus on identifying and mitigating risks within our development lifecycle.

As an Application Security Engineer, you will report directly to the Director of Information Security & Privacy, playing an essential role in maintaining the overall security posture of the company. You'll work closely with the security team, participating in incident response procedures as needed. Our application environment is a hybrid of containers, managing most of our production microservices, and a public cloud-driven services layer based on popular open-source components.

We’re looking for a candidate who thrives in a team setting, collaborates effectively with colleagues across departments, and contributes positively to a dynamic team environment. The ideal individual should be skilled in leveraging the strengths of diverse team members, fostering a culture of open communication, and driving joint initiatives towards successful outcomes.

Your day-to-day

  1. Collaborate with development and product teams to integrate security solutions into business-critical applications.
  2. Assist in creating and refining product security threat models, focusing on security measures tailored to the unique challenges of the insurance sector.
  3. Participate in secure code reviews and product security testing to identify vulnerabilities.
  4. Implement application security best practices throughout the software development lifecycle.
  5. Respond to vulnerabilities identified through internal security testing, prioritizing according to business impact.
  6. Support initiatives to enhance security awareness and practices within the application development teams.
  7. Work closely with compliance teams to ensure that applications adhere to industry-specific regulations and standards.
  8. Document security procedures, best practices, and team initiatives using repeatable patterns.

About you

  • Experience:
    • 5 years of experience in information security, with at least 2 years of experience in application security engineering.
    • Experience in working with software development teams to integrate security into complex application ecosystems.
  • Technical Skills:
    • Familiarity with security-by-design principles and a solid understanding of application security frameworks and standards.
    • Knowledge of OWASP and relevant standards like the Top 10, ASVS and MASVS.
    • Proficiency in at least one programming language and relevant security tools.
  • Soft Skills:
    • Strong communication skills, with the ability to collaborate effectively with development teams and other stakeholders.
    • Ability to work in a fast-paced environment, managing multiple tasks and priorities.

Bonus points

  • Certifications in security architecture or application security (e.g., CSSLP, GWEB, OSCP).
  • Familiarity with the insurance industry or a similarly regulated sector and its impact on application security.
  • Experience with cloud-based security solutions and familiarity with cloud service providers, particularly in relation to application security.
  • Hands-on experience with threat modeling, risk assessment, and vulnerability management.

Salary: $166,000 to $243,000*

*Please note that the final salary offered will be determined based on the selected candidate's skills, and experience, as well as the internal salary structure at Quanata. Our aim is to offer a competitive and equitable compensation package that reflects the candidate's expertise and contributions to our organization.

Additional Details: 

  • Benefits: We provide a wide variety of health, wellness and other benefits.These include medical, dental, vision, life insurance and supplemental income plans for you and your dependents, a Headspace app subscription, monthly wellness allowance and a 401(k) Plan with a company match.
  • Work from Home Equipment: Given our virtual environment— in order to set you up for success at home, a one-time payment of $2K will be provided to cover the purchase of in-home office equipment and furniture at your discretion. Also, our teams work with MacBook Pros, which we will deliver to you fully provisioned prior to your first day.
  • Paid Time Off: All employees accrue four weeks of PTO in their first year of employment.  New parents receive twelve weeks of fully paid parental leave which may be taken within one year after the birth and/or adoption of a child. The twelve weeks is applicable to both birthing and non-birthing parent.
  • Personal and Professional Development: We’re committed to investing in and helping our people grow personally and professionally.  All employees receive up to $5000 each year for professional learning, continuing education and career development.  All team members also receive Udemy subscriptions and access to multiple different coaching opportunities through BetterUp.
  • Location: We are a remote-first company for most positions so you may work from anywhere you like in the U.S, excluding U.S. territories.  Occasional travel may be required for team meetings or company gatherings.  Employees based in the San Francisco Bay Area or in Providence, Rhode Island may commute to one of our local offices as desired.  
  • Hours: We maintain core meeting hours from 9AM - 3PM Pacific time for collaborating with team members across all time zones. 

Quanata, LLC is an equal opportunity workplace. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

If you are a San Francisco resident, please read the City and County of San Francisco's Fair Chance Ordinance notice. https://sfgov.org/olse/sites/default/files/FCO%20poster2020.pdf

This role is employed by Quanata, LLC is a separate company in the State Farm family of companies.
 
If you require a reasonable accommodation, please reach out to your Talent Acquisition Partner for assistance. 

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

Quanata Demographic Question Sets

The following questions are voluntary and intended to help us gain insight into our applicants. Your responses will be kept confidential. You have the option to skip any questions by selecting "Prefer not to say".   

Select...
Select...
Select...
Select...
Select...
Select...