Technical Lead, Application Security Engineer

Remote, USA


Buy and sell the hottest sneakers including Adidas Yeezy and Retro Jordans, Supreme streetwear, trading cards, collectibles, designer handbags and luxury watches.

View company page

Help empower our global customers to connect to culture through their passions.

Why you’ll love this role

This hands-on security engineering position will be part of StockX's Information Security Cloud & Application Engineering  team, leading efforts to enhance security of software development practices. Members of this team work with several stakeholders to ensure appropriate processes, procedures, and controls are adequately designed and implemented to meet StockX security requirements, mitigate risks, and ensure compliance. This is a critical IC role on the StockX Information Security team and will work with several stakeholders in Product, Engineering, Operations, Customer Service, Safety & Trust, & IT.

What you’ll do

  • Assist software developers with secure coding and architecture practices
  • Assist with metric collection and application methodologies for internal information risk management efforts
  • Consult with teams to ensure data is properly handled throughout our environment
  • Collaborate with business, technology, project management, architecture and information security teams to deliver secure solutions that support our business
  • Serve as a liaison between the business, product, and engineering for technical security projects
  • Stay current on information security practices
  • Perform threat modeling, security reviews, and pen testing
  • Manage and monitor bug bounty program
  • Work with information security analysts to ensure visibility and security controls are implemented and maintained
  • Enhance technologies and processes for information security analysts
  • Mentor other information security team members
  • Participation in one or more of the following:
    • Maintaining organization’s security information tools (AlienVault, Snyk, GitGuardian, HackerOne, etc)
    • Conducting code reviews and assisting with remediations across multiple apps and services (PHP, React, iOS, Android, NodeJS, etc)
    • Help drive the shift left movement within StockX by implementing tooling within our CI/CD pipelines (DevSecOps)
    • Driving best practices for AWS Cloud Security in greenfield projects, reviewing current practices, and auditing current policies/infrastructure
    • Serving as a liaison between Compliance and Engineering to ensure we are meeting our regulatory requirements

About you

  • 6 years of application security experience 
  • Bachelor’s degree preferred but not required
  • GIAC, GSEC, CISSP, OSCP or other security certifications preferred
  • Experience with web application security, including OWASP Top 10 vulnerabilities
  • Familiarity with SecDevOps and CI/CD best practices
  • Knowledge of cloud security, including AWS
  • Knowledge of container security, including Docker or Kubernetes
  • Excellent communication and interpersonal skills
  • Strong problem-solving skills and attention to detail
  • Willingness to learn and get up to speed quickly.
  • Excellent analytical, organizational and communication skills. Ability to say No.
  • Experience and ability to mentor senior and junior engineers in the team for best outcomes.


Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation.

Pursuant to the various pay transparency laws/acts, the base salary range is $140,000 to $160,000 plus opportunities for benefits (e.g., medical, dental), equity and discretionary bonuses. Compensation is dependent on geography and may vary.


About Us
StockX is proud to be a Detroit-based technology leader focused on the large and growing online market for sneakers, apparel, accessories, electronics, collectibles, trading cards, and more. StockX's powerful platform connects buyers and sellers of high-demand consumer goods from around the world using dynamic pricing mechanics. This approach affords access and market visibility powered by real-time data that empowers buyers and sellers to determine and transact based on market value. The StockX platform features hundreds of brands across verticals including Jordan Brand, adidas, Nike, Supreme, BAPE, Off-White, Louis Vuitton, Gucci; collectibles from artists including KAWS and Takashi Murakami; and electronics from industry-leading manufacturers Sony, Microsoft, Nvidia, and Apple. Launched in 2016, StockX employs more than 1,000 people across offices and verification centers around the world.     We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. This job description is intended to convey information essential to understanding the scope of the job and the general nature and level of work performed by job holders within this job. However, this job description is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position. StockX reserves the right to amend this job description at any time.
Apply now Apply later
  • Share this job via
  • or

Tags: AlienVault Android Application security Audits AWS CI/CD CISSP Cloud Compliance DevSecOps Docker GIAC GSEC iOS Kubernetes Node.js OSCP OWASP Pentesting PHP Risk management Vulnerabilities

Perks/benefits: Equity

Regions: Remote/Anywhere North America
Country: United States
Job stats:  24  5  1

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.