Senior Security Engineer, App Security

ClickUp ClickUp · Enterprise · United States · Engineering

This role is for a Senior Security Engineer focused on Application Security within a company that heavily integrates AI into its workspace product. The engineer will partner with and embed into existing engineering teams to build and ship secure products, design and build security features, perform threat modeling, and develop security automation. The role emphasizes enabling product engineers to build secure solutions using technologies like Angular, Node.js, and PostgreSQL, hosted on AWS. While the company's product is AI-driven, this specific role is focused on the security of the application and infrastructure, not the direct development or research of AI models.

What you'd actually do

  1. Design, develop and build security features and defenses that protect the entire scope of the ClickUp platform.
  2. Perform threat models, implementation reviews, and security testing; review requirements and designs.
  3. Design and build tools to help with all stages in security prevention, detection, and response; across the full SDLC from code and test, through to deploy and operate.
  4. Embed yourself into existing engineering and product teams, acting as a "security player-coach".
  5. Build security automation for and into the ClickUp platform; design and build secure-by-default infrastructure and applications.

Skills

Required

  • Multiple years of experience in technology / software development.
  • Experience with Angular, Node.js, and PostgresSQL; or similar technologies.
  • An ability to identify and provide a basic assessment of security threats.
  • An understanding of security problems, paired with an ability to suggest solutions to software design problems.
  • Cloud and SaaS experience.
  • Ability to mentor others on technical topics, including security.

Nice to have

  • Past experience with pushing technical initiatives; team, project, or indirect management of technology.
  • Can facilitate a conversation rather than dictate it.
  • 5+ years of software development experience and 1+ year of security-specific experience.
  • Experience with security tools; SAST, DAST, RASP, dependency checkers, SIEM.
  • 2 years of AWS experience; IAM and least-privilege architectures.

What the JD emphasized

  • security features and defenses
  • threat models
  • security testing
  • security prevention, detection, and response
  • secure-by-default infrastructure and applications