Application Security Engineer
About Pagoda
Pagoda is a technology services firm dedicated to developing core components for the NEAR Ecosystem. The company aims to reimagine software development and distribution to increase economic access for all. Their products enable individuals to create opportunities, innovate, and collaborate in an Open Web environment where they have control over their assets and data.
About The Role
Pagoda's security team is expanding and is seeking an Application Security Engineer to bolster the security of their advanced blockchain applications. In collaboration with engineering and product teams, the selected candidate will be instrumental in applying security expertise across the software development lifecycle.
Responsibilities
- Collaborate with engineers to incorporate security best practices in design reviews, threat modeling, code reviews, and penetration testing.
- Engage in secure code review and penetration testing activities to enhance skills with guidance from senior team members.
- Contribute to in-depth security evaluations of web, mobile, and API products to ensure adherence to secure design principles.
- Participate in security training sessions and share knowledge with the wider engineering team to promote a strong security culture.
- Aid in incident response to gain real-world experience and safeguard Pagoda's systems and data.
- Gain exposure to tools like SAST/DAST tools (Snyk, Stackhawk), bug bounty analysis, and risk assessment for personal growth.
Requirements
- 5+ years of experience in application security or a related field with a passion for continuous learning.
- Solid grasp of security fundamentals and common vulnerabilities such as XSS, CSRF, and SQL Injection.
- Ability to identify potential risks and collaborate effectively with engineers on solutions.
- Strong communication skills to convey security concepts to both technical and non-technical audiences.
- Collaborative mindset and eagerness to both learn from and educate others.
Preferred Qualifications
- Familiarity with programming languages like Python, JavaScript, Rust to assist with code review and vulnerability analysis.
- Interest in blockchain technology and enthusiasm for contributing to the security of the Web3 ecosystem.
Interview Process
- Recruiter Call
- Hiring Manager Call
- 1st Round: Bug Bounty Interview, Technical Assessment with Engineering
- Final Round: Meeting with CTO, Pagoda Values Interview
Compensation
The base salary for this role ranges from $153,000 to $170,000 and may vary based on different factors. Specific details about compensation and benefits for various locations will be provided by the recruiter during the hiring process.
Benefits & Perks
- 20 days of flexible PTO annually, plus local holidays
- 2 weeks of paid company-wide wellness weeks
- Health benefits for US employees, with coverage for dependents and HSA + FSA options
- Access to mental health resources and wellness reimbursement
- Generous parental leave and fertility assistance
- Retirement plan (401k) for US employees
- Continued education and home office reimbursement
- Co-working space reimbursement
Company Values
Pagoda is an Equal Employment Opportunity (EEO) employer that values diversity and equal opportunity for all applicants.
Global Data Privacy Notice for Job Candidates
All information collected as part of the Pagoda Careers application process is subject to the company's Privacy Policy. By submitting an application, candidates consent to the use and processing of their data as required.
