Senior/Staff Software Engineer, Product Security

New Today

The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally (>30 times larger than annual consumer e-commerce spend) and rely on vendors more than ever before to run their businesses.Our cofounders started Zip in 2020 to address this seemingly intractable problem with a purpose-built procurement platform that provides a simple, consumer-grade user experience. Within the last 4 years, Zip has created a new category and developed the leading solution in this $50B+ TAM space. Today, the world’s leading companies like OpenAI, Snowflake, Anthropic, Coinbase, and Prudential rely on Zip to manage billions of dollars in spend.We have a world-class team coming from category-defining companies like Airbnb, Meta, Stripe, Salesforce, Apple, and Google. With a $2.2 billion valuation and $370 million in funding from Y Combinator, Tiger Global, BOND, DST Global, and CRV, we’re focused on developing cutting-edge technology, expanding into new global markets, and—above all–driving incredible value for our customers. Join us!Your RoleThe security team at Zip is committed to maintaining the security and confidentiality of our customers’ data. As a Senior Security Software Engineer, you’ll take on a dynamic role, designing and building across domains, from customer-facing security features to infrastructure safeguards. We move quickly to solve a wide range of complex technical and product challenges. While we are an experienced team that can provide constant guidance and mentorship, we value engineers who can autonomously scope and solve complex technical challenges.You willDevelop customer-facing security features, such as account takeover detection systems, universal audit trails, and IP allowlisting, to improve the security capabilities of Zip’s products.Design and implement defensive measures to detect and prevent breaches in Zip’s production infrastructureBuild processes and tooling to enable developers to ship features securelyParticipate in security reviews, threat modeling, table-top exercises, and bug bounty triageLead response to incidents, perform investigations, and communicate clearly to internal and external stakeholdersQualificationsMinimum 4+ years of experience in a security or software engineering role. This role requires software development experience.Experience in enterprise SaaS and/or fintech is preferredExperience with cloud technologies, such as AWS, Kubernetes, and Infrastructure as CodeAn understanding of security best practices and frameworks such as the OWASP Top 10, NIST CSF, and SLSAExposure to compliance and regulatory frameworks such as SOC 2, ISO 27001, and GDPRThe salary range for this role is $150,000 - $210,000. The salary for this position is determined based on a variety of job-related factors that may include location, relevant experience, education, or particular skills and expertise.Perks & BenefitsAt Zip, we’re committed to providing our employees with everything they need to do their best work. Start-up equity Full health, vision & dental coverage️ Catered lunches & dinners for SF employees Commuter benefit Team building events & happy hours Flexible PTO Apple equipment plus home office budget 401k planWe're looking to hire Zipsters and that means hiring people who take ownership, communicate openly, have an underdog mindset, and are excited to increase the pace of innovation for every business in the world. We encourage all candidates to apply even if your experience doesn't exactly match up to our job description. We are committed to building a diverse and inclusive workspace where everyone (regardless of age, religion, ethnicity, gender, sexual orientation, and more) feels like they belong. We look forward to hearing from you! #J-18808-Ljbffr
Location:
San Francisco, CA, United States