Security Engineer

Atlanta, Georgia, United States

Applications have closed
About Us Our mission is to make hourly work easier for local businesses and hourly workers. Homebase currently serves more than 100,000 small (but mighty) businesses with everything they need to manage their hourly teams: employee scheduling, time clocks, payroll, team communication, hiring, onboarding, and compliance. Just don’t call us “Human Capital Management.” We have built tools for the busiest businesses, so owners and employees can spend less time on bullsh*t and more time on what matters. The Homebase team brings small business expertise from Intuit, Square, OpenTable, Yelp, Gusto, and First Data. Homebase is backed by leading venture investors Bain Capital Ventures, Baseline Ventures, Cowboy Ventures, Khosla Ventures, Plus Capital, and GGV Capital.   The Job
As a Security Engineer at Homebase, you will work in a Product Security/Application Security role to improve the security and privacy around Homebase customer data that enables thousands of small businesses to safely and reliably manage their operations. By reviewing upcoming releases, identifying security vulnerabilities, implementing systemic improvements, and working with all teams in the organization to remediate issues. You will play a leading role in protecting the data of our customers and in securing the integrity of our systems.
  • You’ll balance security with end-user efficiency and business needs
  • You’ll help other engineers design more secure systems via design input and code review.
  • You’ll manage our Bug Bounty program, triage incoming reports, and work with the rest of the engineering team to address vulnerabilities.
  • You’ll be a champion for security across the entire business.
Qualifications
  • 3+ years of experience on an internal application security team or related discipline.
  • Experience working with web and mobile applications teams
  • Knowledge of common attacks and exploitation techniques
  • Knowledge of  threat modeling and architecture design review 
  • Knowledge of network and related web protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)
  • Strong communication skills.
  • Bachelor's degree in Computer Science or Engineering disciplines or equivalent required
Desired Qualifications
  • Knowledge of development best practices, both for mobile and web applications.
  • Scripting experience
  • Knowledge of Git, Github, and development using pull requests.
  • Knowledge of product incident response.
  • Development experience in ruby on rails applications.
  • Experience triaging and working in bug bounty programs
  • Experience in using standard Security Assessment and Penetration Testing tools such as BurpSuite, Metasploit, and OWASP Zap.
  • 5+ years of experience working on an internal application security team
Homebase Team Attributes: If you resonate with these traits, you may be a Homie!
  • Gets shit done - Moves quickly and with urgency to deliver results. Strong bias to action.
  • Strong work ethic - Willing to work hard and put in the time to accomplish outsized goals.
  • Learning mindset - Proactive in personal development. Highly curious and driven to learn.
  • Sets a high bar - Expects personal and team performances to be world-class.
  • Humble - Delivers exceptional results without an ego. Shares credit broadly.
  • Team Player - Collaborative. Motivates and creates positive environments for colleagues and teams.

What We Offer You 

  • Stock Options - everyone is an owner
  • Comprehensive Insurance Plans
  • 401(k) program +4% company match
  • Remote work with hybrid option in multiple locations
  • Top-of-the-line equipment and home office $$
  • Annual Holidays and Accrued PTO
  • A dynamic, well-connected, productive team
  • Fun company activities

At Homebase, we value our differences, and we encourage all to apply. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Homebase is proud to be an equal opportunity employer and participant in the U.S. Federal E-Verify program.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Application security Burp Suite Compliance Computer Science GitHub Incident response Metasploit OWASP Pentesting Privacy Product security Ruby Scripting Security assessment TCP/IP Vulnerabilities

Perks/benefits: 401(k) matching Career development Equity Insurance

Region: North America
Country: United States
Job stats:  10  1  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.