Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Software Security Engineer image - Rise Careers
Job details

Senior Software Security Engineer

Vistar Media is the home of out-of-home (OOH). As a global ad tech company and the world's largest digital out-of-home (DOOH) advertising marketplace, we offer technology designed to make buying and selling OOH media easier. Our goal is simple: to help the world's marketers leverage OOH's unique ability to motivate and delight. 

From strategic partnerships with major media owner networks to executing impactful campaigns with renowned global brands such as Nestlé, Porsche, Target, and Levi's, our team is filled with passionate, innovative, and collaborative problem solvers, engaging and entertaining consumers like you in the real world. Find your home in out-of-home - find your people at Vistar.

About the role:

We are seeking a Senior DevSecOps Engineer, with extensive experience in security vulnerability remediation, cloud infrastructure, and strategic planning. The ideal candidate is adept at identifying and fixing security vulnerabilities in codebases written in languages such as Python, TypeScript, Go, Java, and Scala. This role is ideal for a Software Engineer with a focus on Security, who thrives working independently and collaborating in a cross-functional environment with multiple engineering teams, leadership, and non-technical peers. This is a great opportunity to join an innovative company that prioritizes security and continuous improvement.

What you'll do:

  • Security & Vulnerability Management:

    • Conduct code reviews, static and dynamic application security testing (SAST and DAST), and penetration testing to identify vulnerabilities and recommend remediation strategies.

    • Implement automated security testing and monitoring tools to maintain a robust security posture.

  • Cloud Infrastructure:

    • Design, deploy, and manage secure cloud infrastructure solutions.

    • Integrate security best practices across cloud services and platforms.

  • Collaboration & Communication:

    • Excel in a strong, collaborative work environment while effectively managing independent tasks.

    • Provide technical guidance and mentorship to junior team members and peers.

    • Collaborate with development, operations, and product teams to plan and implement security enhancements.

  • Security Tooling & Monitoring:

    • Manage and optimize security tooling including SIEM systems, vulnerability scanning tools, and Zero Trust Architecture (ZTA) VPN solutions.

    • Leverage related services to ensure comprehensive threat detection, incident response, and secure remote access.

  • Continuous Improvement:

    • Stay updated with the latest trends, tools, and best practices in DevSecOps.

    • Drive process improvements and advocate for security-first development practices across teams.

What experience we're looking for:

  • Bachelor's Degree in a technical field (e.g. engineering, computer science, etc.), or equivalent practical experience.

  • 8+ years of professional work experience as a developer.

  • 3+ years of work experience in software development and fixing security vulnerabilities in languages such as Python, TypeScript, Go, Java, and Scala.

  • 5+ years of work experience in DevSecOps or other security-focused software development role, with a strong focus on cloud infrastructure.

  • Expertise in public cloud platforms (AWS - preferred, Azure, GCP, etc) and related security services.

  • Proficiency with security tooling including IDS, IPS, SIEM, Zero Trust Architecture (ZTA VPN), and related services.

  • Familiarity with automation tools, CI/CD pipelines, and containerization technologies.

  • Strong understanding of security protocols and technologies (TLS, HTTPS, OAuth, etc).

  • Deep understanding of security frameworks and compliance standards.

Who you are

  • Proven history of succeeding in challenging projects that have a significant impact on the organization’s overall security posture.

  • Thrive off opportunities for professional growth and career advancement in a fast-paced, technology-driven setting.

  • Enjoy a strong, collaborative work environment that values teamwork and open communication.

  • Excellent problem solving skills and attention to detail.

  • Demonstrated ability to work both independently and collaboratively in a dynamic environment.

  • Strong communication skills with the ability to communicate security risks and recommendations effectively to technical and non-technical stakeholders.

What we offer:

  • Flexible, fun start-up environment and culture

  • An approachable and accessible C-Suite.

  • Comprehensive health benefits.

  • 401k + match.

  • Quarterly Lifestyle Stipend.

  • Unlimited PTO and summer Fridays.

  • Company-wide and team specific entertainment budgets for both in-person and virtual team building.

  • A flexible hybrid work environment, with a fully stocked kitchen, weekly catered lunches, and casual attire while in office.

  • Sponsored Volunteer Events and Vistar Gives Back program.

  • An awesome and supportive bunch of people to work with and learn from.

Recruiting fraud is a serious issue facing jobseekers. Please be aware that Vistar Media would never require personal information (such as bank account information) during the interview process. Should an employee from Vistar Media reach out to you, that communication will come from an @vistarmedia.com email address. During a typical interview process, you will have several phone, video, and/or in-person interviews with multiple Vistar Media employees before a hiring decision is made. We do not require payment from applicants for training or other costs incurred, nor do we offer compensation before hiring.

If you’re ambitious, highly driven, and interested in making an impact, Vistar is the place for you. Apply to join our team… we’ll see you out there.

Vistar Media Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Vistar Media DE&I Review
4.3 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Vistar Media
Vistar Media CEO photo
Michael Provenzano
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Software Security Engineer, Vistar Media

At Vistar Media, we are seeking a talented Senior Software Security Engineer to join our dynamic team in Philadelphia. As a global leader in out-of-home (OOH) advertising technology, we pride ourselves on enhancing the world's largest digital out-of-home marketplace. If you're passionate about security and love working in an innovative environment, you'll fit right in! In this role, you will spearhead security and vulnerability management by conducting comprehensive code reviews and implementing automated testing. We're looking for someone with a strong background in cloud infrastructure, particularly with public cloud platforms like AWS, Azure, or GCP, who can design and manage secure solutions. Collaboration is key here at Vistar; you'll work closely with cross-functional teams, mentor junior engineers, and communicate security protocols to both technical and non-technical peers. We value continuous improvement, so staying updated with the latest trends and tools in DevSecOps is vital. If you have at least 8 years of development experience, with a focus on security in languages such as Python, TypeScript, and Java, along with a keen eye for detail and problem-solving skills, we'd love to meet you! Join us and contribute to impactful campaigns for renowned global brands while enjoying a flexible, fun work culture that emphasizes teamwork and professional growth. Discover your potential with Vistar Media today!

Frequently Asked Questions (FAQs) for Senior Software Security Engineer Role at Vistar Media
What are the responsibilities of a Senior Software Security Engineer at Vistar Media?

As a Senior Software Security Engineer at Vistar Media, your primary responsibilities include conducting security & vulnerability management tasks such as code reviews, static and dynamic application security testing, and penetration testing. You'll also be responsible for designing and managing secure cloud infrastructure, collaborating with various engineering teams to implement security best practices, and continually improving our security posture with automated tools.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Software Security Engineer position at Vistar Media?

To be considered for the Senior Software Security Engineer position at Vistar Media, candidates should have a Bachelor's Degree in a technical field or equivalent practical experience. Ideally, you will have 8+ years of professional development experience, 3+ years focused on fixing security vulnerabilities in programming languages like Python, TypeScript, or Go, and 5+ years in a security-oriented software role with strong cloud infrastructure expertise.

Join Rise to see the full answer
How can I excel in the Senior Software Security Engineer role at Vistar Media?

Excelling as a Senior Software Security Engineer at Vistar Media involves maintaining a proactive approach to security, keeping abreast of the latest trends in security protocols, and demonstrating strong communication skills to relay security risks and measures effectively. Collaborating with teams from different functions and mentoring junior staff will also contribute to your success in this role.

Join Rise to see the full answer
What technology stack is used by Senior Software Security Engineers at Vistar Media?

Senior Software Security Engineers at Vistar Media typically work with cloud service platforms like AWS, Azure, and GCP, as well as a variety of programming languages including Python, TypeScript, Java, and Scala. Familiarity with security tools such as SIEM, Zero Trust Architecture, and vulnerability scanning tools is also essential for the role.

Join Rise to see the full answer
What kind of work environment does Vistar Media offer for Senior Software Security Engineers?

Vistar Media offers a flexible and fun work environment that promotes professional growth and collaboration. As a Senior Software Security Engineer, you will be part of a supportive team culture, with great benefits including unlimited PTO, a hybrid work model, and opportunities for team-building events. The company cares about employee satisfaction and well-being, creating a welcoming atmosphere for personal and professional development.

Join Rise to see the full answer
Common Interview Questions for Senior Software Security Engineer
Can you describe your experience with security vulnerability remediation?

When answering this question, provide specific examples from your past roles where you've successfully identified and fixed vulnerabilities. Highlight your approach, the tools you used, and the positive outcome of your work to demonstrate your practical experience and expertise.

Join Rise to see the full answer
How do you stay updated with the latest trends and tools in cybersecurity?

To answer this question, discuss the resources you utilize to stay informed, such as industry blogs, webinars, and professional organizations. Mention any certifications you pursue, or conferences you attend to reinforce your commitment to continuous learning in the field of cybersecurity.

Join Rise to see the full answer
What is your experience with automated security testing?

In your response, talk about the automated tools you've utilized for security testing, such as SAST and DAST. Provide insights into how you've integrated these tools into the development lifecycle and the impact of automation on your security posture.

Join Rise to see the full answer
Describe a challenging project you've worked on as a Software Security Engineer.

Be ready to discuss a specific project where you faced significant challenges. Explain the situation, your role in the process, the security measures you implemented, and how you overcame any obstacles to achieve success.

Join Rise to see the full answer
How do you approach collaboration with non-technical stakeholders?

For this question, illustrate your communication skills and how you tailor your messages to bridge the gap between technical jargon and non-technical understanding. Provide examples of effective collaboration strategies you've used to ensure that all stakeholders are on the same page regarding security initiatives.

Join Rise to see the full answer
What are the key security frameworks you are familiar with?

Discuss the security frameworks you have worked with, such as NIST, ISO 27001, or CIS controls. Highlight how you've applied these frameworks in real-world scenarios to understand compliance and improve security measures.

Join Rise to see the full answer
Can you explain your experience with cloud security best practices?

In your response, delve into the specifics of your experience with securing cloud environments. Discuss best practices you've pursued, such as implementing Identity and Access Management (IAM), data encryption, and security monitoring using tools like AWS security services.

Join Rise to see the full answer
What steps would you take to implement a Zero Trust Architecture?

When addressing this question, outline the principles of Zero Trust Architecture and the steps you consider necessary for implementation, such as segmenting networks, enforcing least privilege access, and continuous monitoring of user activities.

Join Rise to see the full answer
How do you prioritize security incidents during your work?

In addressing this question, explain your methodology for evaluating incidents based on severity and impact. Discuss tools or frameworks you utilize to assess and prioritize risks effectively.

Join Rise to see the full answer
What programming languages are you proficient in and how do you leverage them for security?

Provide a list of programming languages you are comfortable with, and discuss how you use them for security tasks, such as building secure code, performing static analysis, or implementing security features. Real-world examples will reinforce your points.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted yesterday
Photo of the Rise User
Gcore Remote 2-4 Rue Edmond Reuter, 5326 Contern, Luxembourg
Posted 10 days ago
Posted 14 days ago
Photo of the Rise User
Datacom Remote No location specified
Posted yesterday
Photo of the Rise User
Posted 14 days ago
Photo of the Rise User
Dental Insurance
Vision Insurance
Performance Bonus
Photo of the Rise User
Newsela Remote Remote - Argentina; Brazil; Mexico
Posted 4 days ago
Inclusive & Diverse
Mission Driven
Collaboration over Competition
Growth & Learning
Medical Insurance
Dental Insurance
Vision Insurance
Learning & Development
Paid Time-Off
Sabbatical
WFH Reimbursements
Flex-Friendly
Photo of the Rise User
Posted 6 hours ago
Photo of the Rise User
Canadian Bank Note Company Remote 18 Auriga Dr, Nepean, ON K2E 7T9, Canada
Posted 12 hours ago

Vistar Media is the home of out-of-home. Out there, in the streets, ad space intersects time and place. It’s a part of life. OOH campaigns inform, entertain, attract - and they can change the course of someone’s afternoon. At Vistar Media, we fa...

34 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 18, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!