Ladder logo

SecOps/AppSec Engineer

Ladder

RemoteFull timeMid level$109k – $144kPosted today
Apply with JobAssist

About the role

Who you are

  • The ideal candidate is well-rounded and has the ability to interact with all levels of management and external auditors, and operate effectively in a rapidly scaling, dynamic environment
  • We are looking for someone who is organized, self-motivated, has excellent problem-solving and writing skills, and enjoys working with people in a challenging and fast-paced environment
  • An Experienced Security Professional: 4+ years of software engineering and/or cybersecurity experience, backed by a strong foundation in Computer Science, Cyber Security, or a related field
  • Clojure-Capable: Hands-on experience coding in Clojure and working within the JVM environment. You are comfortable reading functional code, understanding immutable data structures, and collaborating directly with backend engineers on code-level fixes
  • A Cloud SecOps Practitioner: Hands-on experience securing modern cloud infrastructures, as well as experience working incident response
  • An Autonomous Systems Thinker: Thrive in dynamic environments. You don't just clear alerts; you look for the root cause of issues to design security frameworks that prevent entire classes of vulnerabilities from happening in the first place
  • Certified Professional: Hold baseline certifications such as CompTIA Security+ or equivalents. Having an advanced credential like the CISSP is highly preferred and considered a major plus

What the job involves

  • We are looking for a cybersecurity unicorn. A Security Engineer / Analyst who brings a rare blend of application security engineering and risk management maturity
  • In this role, you will be the driving force behind our vulnerability management lifecycle, balancing day-to-day security operations with development-facing vulnerability management and compliance
  • Your primary mission will be embedded within our development lifecycles, taking ownership of application security vulnerability management for our engineering teams
  • Because our backend infrastructure runs heavily on Clojure, you won't just be running automated scanners, you will actively look at code and leverage your functional programming experience to strengthen our shift-left security philosophy
  • Beyond AppSec, you will wear multiple hats: monitoring our cloud infrastructure and responding to alerts, conducting security risk reviews, supporting compliance audits, and ensuring our day-to-day workspace remains locked down
  • In this role, you will have the opportunity to drive innovation within the reporting function and help build out the accounting function
  • Secure the Code (Primary): Partner directly with development teams to champion application security vulnerability management. You will triage vulnerabilities within a high-scale Clojure ecosystem and assist with remediation code fixes
  • Security Ops: Configure, fine-tune, and monitor our cloud security posture leveraging Security Operations tools (SIEM, SOAR, CSP, CNAPP) to detect and respond to threats in real time
  • Champion Governance & Risk: Conduct thorough Security Reviews and risk assessments on internal architecture, third-party vendors, and APIs to ensure alignment with our corporate risk tolerance and compliance standards
  • Protect the Workspace: Maintain and optimize our day-to-day corporate workspace security, ensuring identity access management, device compliance, and productivity tools are highly secure yet frictionless for the team
  • Drive Technical Excellence: Act as a security advocate across teams. Mentor engineers on secure coding practices, establish secure defaults, and make practical risk decisions that scale with our growth
  • Technologies Used:
  • Backend & Code: Clojure, JVM, TypeScript, JavaScript
  • Cloud & Infrastructure: GCP, Kubernetes, Docker, Terraform, GraphQL
  • Security & Data Operations: Google Security Command Center, Chronicle, Datomic, BigQuery, Kafka

Benefits

  • One-time stipend to support remote and hybrid work
  • Recurring stipend to cover WFH costs
  • 401k Match: Ladder matches your 401(k) contribution, dollar-for-dollar, up to 4% of your salary.
  • Commuter Benefits: We offer a pre-tax transit account, as well as free employee parking.
  • Catered Lunch: In-office employees get catered lunch every day from a variety of local restaurants.
  • Ladder Fit: Ladder reimburses up to $50 per month for eligible wellness-related expenses.
  • Baby Bonding: We offer 10 weeks paid leave when you welcome a new addition.
  • Vacation: We encourage our employees to take time off so they can return relaxed and refreshed.
  • Awesome Benefits: We offer medical, dental, vision, life, FSA, and short & long term disability.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Ladder was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.