Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Application Security Engineer image - Rise Careers
Job details

Senior Application Security Engineer

Founded in 2012, EasyPost is a YC unicorn whose mission is to make shipping simple for businesses, from garage startups to the Fortune 500. Shipping, now more than ever, is the backbone of the global economy, but integrating the technology-enabled operations of a modern business with the low-tech and complex shipping industry has always been a challenge. EasyPost solves this problem with the first developer-friendly REST API for shipping, and we continue to push boundaries and discover new ways to simplify shipping for all. Our team is rapidly growing, and this is the perfect time to get on board. Join us, and help build the shipping infrastructure of the future.


Position Summary: 


The Senior Application Security Engineer will play a critical role in maintaining and improving the security of EasyPost’s growing and evolving logistics ecosystem. Responsibilities will include identifying, planning, and completing high-impact security projects, reviewing new proposed product features, building new security systems and programs. The Senior Security Engineer will leverage their experience and creativity to protect millions of users, the company, and our partner organizations against both identified and emerging security risks.



Essential Duties and Responsibilities:


The essential functions include, but are not limited to the following:


o Lead the design, building and maintenance of security systems and infrastructure that support the organization's evolving business and security goals.

o Collaborate with other teams to integrate security and privacy controls and technology into the company’s overall planning and development process from project inception to project delivery.

o Build systems and programs that help security at EasyPost to scale efficiently in both breadth and depth of coverage.

o Embrace “shift-left” DevSecOps patterns, including infrastructure-as-code and Continuous Integration/Continuous Delivery design patterns that move security feedback to the earliest phases of product development and provide faster feedback to partner teams.

o Design and build key competitive security features within the product itself that will support continued business growth among security-conscious customers.

o Build and maintain security alerting infrastructure that delivers timely, relevant, and actionable alerts directly to internal staff, customers, and users.

o Create and maintain self-service documentation, training material, and knowledge base resources that help developers be more productive and write safer code.

o Work directly with M&A entities to integrate their products and improve the overall security posture of their existing development and support environments.


Minimum Education & Experience Qualifications:


o Bachelor's degree in computer science, management information systems, or related field.

o 8+ years of related experience, master’s degree and 6+ years of related experience, or equivalent related work experience. 

o Comfortable writing production-ready code daily in at least two of the following languages: Python, Ruby, Go, or Rust.

o Ability to design systems that are simple to understand, maintainable, scalable, and resilient.

o Prior experience securing large-scale web applications and/or Application Programming Interfaces (APIs), including performing security design reviews, vulnerability assessments, and building testing strategies for logic flaws.

o The ability to understand and communicate concepts around threat modeling and risk management, including to both technical and non-technical stakeholders.

o Proven history of building strong partnerships with Engineering and Product teams to deliver world-class products and features.

o Working knowledge of several compliance and regulatory frameworks (SOC2, ISO 27001, SOX/ITGC, HIPAA, GDPR, CCPA, etc…)

o Experience in assessing risk and selecting key objectives during the vendor management lifecycle for software, hardware, cloud, and software-as-a-service vendors.

o Deep knowledge of how to build and maintain mixed computing environments (Linux, Windows, Mac OS, and mobile devices).

o Past experience with migrating applications and services to public cloud providers (AWS, GCP, Azure, etc…)


$125,000 - $170,000 a year

The posted salary range represents the base compensation for this role. Actual compensation may vary based on factors including, but not limited to, experience, education, skills, geographic location, and internal equity.

What We Offer:


o Comprehensive medical, dental, vision, and life insurance

o Competitive compensation package and equity

o Monthly work from home stipend of $50

o Flexible work schedule and paid time off

o Collaborative culture with a supportive team

o A great place to work with unlimited growth opportunities

o The opportunity to make massive contributions at a hyper-growth company

o Make an impact on a product helping ship millions of packages per day


Data Privacy Notice for Job Applicants:

For information on personal data processing, please see our Privacy Policy: https://www.easypost.com/privacy


"EasyPost is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law."


To be considered for this position, you must be authorized and based in the United States.

EasyPost Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
EasyPost DE&I Review
4.6 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of EasyPost
EasyPost CEO photo
Jarrett Streebin
Approve of CEO

Average salary estimate

$147500 / YEARLY (est.)
min
max
$125000K
$170000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Application Security Engineer, EasyPost

Join EasyPost as a Senior Application Security Engineer and become a key member of a pioneering team dedicated to redefining the shipping experience for businesses around the globe. Founded in 2012, EasyPost has been on a mission to simplify shipping through our innovative REST API that powers operations from startups to Fortune 500 companies. In this remote position, you will take the lead on high-impact security projects, ensuring our logistics ecosystem remains secure as it grows. Your role will involve collaborating with various teams to weave security into our development processes and designing scalable security systems. If you're passionate about addressing security risks from the early stages of product development and have the expertise to build competitive security features, this could be your moment to shine. Leveraging your years of experience, you'll create robust security infrastructures that empower millions of users, safeguard our organization, and enhance partnerships. Plus, you'll play a vital role in educating our developers through self-service documentation and training materials. We welcome you to embrace a collaborative culture where your contributions directly support our hyper-growth environment. If you’re ready to be part of a team that’s making waves in the logistics industry, EasyPost is the place to be!

Frequently Asked Questions (FAQs) for Senior Application Security Engineer Role at EasyPost
What are the responsibilities of a Senior Application Security Engineer at EasyPost?

As a Senior Application Security Engineer at EasyPost, you will lead the design, building, and maintenance of security systems that align with the organization’s business goals. You'll collaborate closely with various teams to integrate security and privacy controls from project inception to delivery. Additionally, you'll create scalable security programs, embrace DevSecOps patterns, and design key competitive security features that safeguard our customer data.

Join Rise to see the full answer
What qualifications are needed for the Senior Application Security Engineer position at EasyPost?

To qualify for the Senior Application Security Engineer role at EasyPost, candidates should hold a Bachelor’s degree in computer science or a related field, with a minimum of 8 years of experience in the field. Familiarity with production-ready programming in languages like Python, Ruby, Go, or Rust is essential, along with experience in securing large-scale web applications and APIs. Strong communication skills for engaging both technical and non-technical stakeholders are also crucial.

Join Rise to see the full answer
How does EasyPost foster a collaborative culture for Senior Application Security Engineers?

At EasyPost, collaboration is key. Senior Application Security Engineers work closely with Engineering and Product teams to create secure products and features. The role encourages interaction across various departments, ensuring that security measures are integrated throughout the development process. This collaborative approach helps enhance product integrity and fosters a supportive atmosphere where innovation thrives.

Join Rise to see the full answer
What growth opportunities are available for Senior Application Security Engineers at EasyPost?

EasyPost offers numerous growth opportunities for Senior Application Security Engineers. With a focus on continuous improvement, employees have access to training resources, mentorship programs, and a culture that encourages professional development. As EasyPost is a rapidly growing company, there are potential paths for advancement into higher-level security roles or team leadership positions.

Join Rise to see the full answer
What is the expected salary range for the Senior Application Security Engineer role at EasyPost?

The salary range for the Senior Application Security Engineer position at EasyPost is between $125,000 and $170,000 per year. Actual compensation may vary based on factors such as experience, education, and location. This competitive compensation package includes not only a base salary but also benefits such as medical, dental, vision insurance, and equity opportunities.

Join Rise to see the full answer
Common Interview Questions for Senior Application Security Engineer
What experience do you have with securing APIs as a Senior Application Security Engineer?

When answering this question, highlight specific projects where you successfully implemented security measures for APIs. Discuss your familiarity with tools and methodologies for conducting security design reviews and vulnerability assessments. Providing concrete examples will demonstrate your expertise and proactive approach to API security.

Join Rise to see the full answer
How do you approach threat modeling in application security?

Discuss your method for identifying potential threats and vulnerabilities within a system. Share how you prioritize risks based on their potential impact and likelihood, and explain how you communicate these findings to both technical and non-technical stakeholders to inform risk management strategies.

Join Rise to see the full answer
Can you explain a time when you collaborated with a team to address a security issue?

Use the STAR method to share a specific instance where your collaboration led to a positive outcome. Describe the problem, the actions you took with your team, and the results achieved. This will showcase your teamwork skills and your commitment to fostering a collaborative security environment.

Join Rise to see the full answer
What programming languages are you proficient in, and how have you applied them in security?

Identify the programming languages you are skilled in, such as Python, Ruby, Go, or Rust. Discuss how you've used these languages to write secure code, build security tools, or automate security processes. Highlighting practical applications of your coding abilities in the context of security will show your technical competence.

Join Rise to see the full answer
How do you keep up with the latest security trends and threats?

Explain your methods for staying informed about current security trends, such as following industry blogs, participating in forums, or attending conferences. Mention any specific resources or networks you rely on, which will demonstrate your commitment to ongoing professional development in the ever-evolving field of security.

Join Rise to see the full answer
What is your experience with compliance frameworks relevant to application security?

Talk about your experience working with compliance frameworks like SOC2, GDPR, or HIPAA. Provide examples of how you successfully implemented compliance measures in previous roles, showcasing your understanding of regulatory requirements and their importance in the security landscape.

Join Rise to see the full answer
Describe a security incident you managed and the outcome.

Share a particular security incident where you played a significant role in its management. Discuss the issue, your response strategy, and the lessons learned from the experience. This will illustrate your incident management skills and ability to learn and adapt from challenges.

Join Rise to see the full answer
What strategies do you use to educate development teams about secure coding practices?

Discuss your approach to creating training materials and documentation that help developers understand secure coding practices. Emphasize the importance of integrating security into the development lifecycle and how you ensure developers can write safe and secure code.

Join Rise to see the full answer
What are some of the key metrics you use to measure the effectiveness of security initiatives?

Outline the metrics you consider crucial for evaluating the success of security initiatives, such as the number of vulnerabilities found, the time taken to remediate them, and user feedback on security features. Discuss how tracking these metrics can help drive continuous improvement in security practices.

Join Rise to see the full answer
How would you handle a situation where a security vulnerability is identified late in the development cycle?

Explain your problem-solving approach in this scenario, emphasizing swift communication with the development team and stakeholders. Highlight the importance of assessing the risk, determining the urgency of the fix, and implementing a resolution while minimizing disruptions to the project's timeline.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 3 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as a Technology Auditor and contribute to our mission of enhancing organizational value through independent risk-based assurance.

Photo of the Rise User
NECSWS Remote Hybrid, United Kingdom, England, United Kingdom
Posted 7 days ago

Join NEC Software Solutions as a Cyber Security Engineer to enhance their security posture and make a significant contribution to the safety of public services.

Photo of the Rise User
Posted 13 days ago

Join Ferguson as a Lead SQL Database Administrator and play a critical role in supporting our enterprise-level systems.

Photo of the Rise User
Thaloz Remote No location specified
Posted 11 days ago

Become an essential part of our team as a PowerApps Developer, focusing on enhancing operational efficiency through custom software solutions.

Photo of the Rise User
ARSIEM Remote Hybrid, Remote, Columbia, MD
Posted 9 days ago

We're seeking an experienced ISSO/IA to enhance information security practices at ARSIEM Corporation in a hybrid work environment.

As a Junior Technical Requirements Analyst at ManTech, you will support project requests by capturing and analyzing business and technical requirements in a fully remote role.

SAP Fioneer Remote No location specified
Posted 2 days ago

Join SAP Fioneer's innovative team as a Cyber Defense Engineer and play a crucial role in strengthening their cybersecurity operations.

Posted 11 days ago

C Mauritius invites a motivated IT Coordinator to enhance its technology and hospitality services.

Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Rapid Growth
Passion for Exploration
Dare to be Different
Dental Insurance
Life insurance
Health Savings Account (HSA)
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Mental Health Resources
401K Matching
Paid Time-Off
Snacks
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Customer-Centric
Fast-Paced
Growth & Learning
Medical Insurance
Dental Insurance
401K Matching
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Flex-Friendly
Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Deliver the most reliable logistics technology platform for businesses of all sizes to ship sustainably.

18 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 16, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
o
Someone from OH, Cincinnati just viewed Marketing and Communications Consultant at osu
Photo of the Rise User
Someone from OH, Toledo just viewed Registered Nurse (Part-time) at Calibrate
Photo of the Rise User
Someone from OH, Toledo just viewed Clinical Research Associate II at Alimentiv
Photo of the Rise User
Someone from OH, Cleveland just viewed IT Support Engineer at Level AI
Photo of the Rise User
Someone from OH, Dayton just viewed Customer Content Specialist at Cision
Photo of the Rise User
Someone from OH, Cuyahoga Falls just viewed Senior Corporate Communications Manager at Bumble Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at Workday
Photo of the Rise User
Someone from OH, Cincinnati just viewed Financial Planning and Analysis Lead at JLL
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Financial Analyst at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Operations at American Express
Photo of the Rise User
Someone from OH, Cincinnati just viewed Strategic Finance Analyst, Corporate at Benchling
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Analyst, Project Finance at Apex Clean Energy
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior FP&A Analyst, Sales at GitLab
Photo of the Rise User
Someone from OH, Cincinnati just viewed FP&A Analyst at Lithic
Photo of the Rise User
15 people applied to Junior Security Engineer at Epic
Photo of the Rise User
Someone from OH, Westerville just viewed Summer Internship - Public Health Data Science at Cotiviti