SecOps/AppSec Engineer (Clojure Required)
About the role
About the Role
We are looking for a cybersecurity unicorn. A Security Engineer / Analyst who brings a rare blend of application security engineering and risk management maturity. In this role, you will be the driving force behind our vulnerability management lifecycle, balancing day-to-day security operations with development-facing vulnerability management and compliance.
Your primary mission will be embedded within our development lifecycles, taking ownership of application security vulnerability management for our engineering teams. Because our backend infrastructure runs heavily on Clojure, you won't just be running automated scanners, you will actively look at code and leverage your functional programming experience to strengthen our shift-left security philosophy. Beyond AppSec, you will wear multiple hats: monitoring our cloud infrastructure and responding to alerts, conducting security risk reviews, supporting compliance audits, and ensuring our day-to-day workspace remains locked down.
The ideal candidate is well-rounded and has the ability to interact with all levels of management and external auditors, and operate effectively in a rapidly scaling, dynamic environment. We are looking for someone who is organized, self-motivated, has excellent problem-solving and writing skills, and enjoys working with people in a challenging and fast-paced environment. In this role, you will have the opportunity to drive innovation within the reporting function and help build out the accounting function.
Please note, this is a remote role based in one of the 23 States Ladder is currently hiring in - AZ, CA, CO, CT, FL, GA, IA, KS, MA, MD, MN, NC, NH, NJ, NV, NY, OH, OR, PA, TX, VA, WA, WI with the exception of the following cities: SF Bay Area, New York City, and Seattle.
Please note, Ladder is not currently sponsoring or transferring OPT or H1-B visa's.
What You'll Do
- Secure the Code (Primary): Partner directly with development teams to champion application security vulnerability management. You will triage vulnerabilities within a high-scale Clojure ecosystem and assist with remediation code fixes.
- Security Ops: Configure, fine-tune, and monitor our cloud security posture leveraging Security Operations tools (SIEM, SOAR, CSP, CNAPP) to detect and respond to threats in real time.
- Champion Governance & Risk: Conduct thorough Security Reviews and risk assessments on internal architecture, third-party vendors, and APIs to ensure alignment with our corporate risk tolerance and compliance standards.
- Protect the Workspace: Maintain and optimize our day-to-day corporate workspace security, ensuring identity access management, device compliance, and productivity tools are highly secure yet frictionless for the team.
- Drive Technical Excellence: Act as a security advocate across teams.