Sorry, this listing is no longer accepting applications. Don’t worry, we have more awesome opportunities and internships for you.

Application Security Engineer (Security Consulting) - Speciality in Python

Twitter

Application Security Engineer (Security Consulting) - Speciality in Python

San Francisco, CA
Full Time
Paid
  • Responsibilities

    Job Description

    WHAT YOU’LL DO

    As a Security Engineer, you'll join a team of talented security engineers working to reduce risk across the company. We work with engineering and product teams to provide security expertise during each phase of the SDLC and take a leadership role in driving security initiatives. We identify recurring classes of security problems, find the root cause, and develop generalized and creative solutions to reduce the occurrence of application vulnerabilities at scale. We strive to advocate and teach security to engineers. Additionally, we assist with third-party security assessments and operate Twitter’s bug bounty program.

  • Qualifications

    Qualifications

    WHO YOU ARE 

    The ideal individual has both application security expertise and development experience. They have in-depth knowledge of application security and can identify potential risks in designs, code, or in deployed applications. They should also have experience with threat modeling, security reviews, pen-testing and providing security guidance to development teams. They recognize the importance of building security solutions that scale both technically and organizationally, and adapt to changing business requirements. They enjoy advocating security by writing, giving talks, or hosting educational sessions for developers.

    QUALIFICATIONS

    YOU WILL MEET MOST (BUT NEED NOT MEET ALL) OF THE FOLLOWING POINTS:

    • Bachelor’s or advanced Degree in Computer Science or closely related field.

    • 4+ years of relevant experience.

    • Knowledge of Python, and common Python web frameworks frameworks (e.g. Django).

    • Expertise with web security standards such as CSP, CORS, and emerging web security technologies.

    • Understanding of security challenges in service architectures or large distributed systems.

    • Expertise with browser security controls and web application security best practices.

    • Experience with finding security design flaws and implementation bugs. 

    • Experience building security and process improvement tools. 

    • Experience communicating security concerns and issues to non-technical audiences.

    • Experience building tools and processes to reliably identify security issues and logic flaws across large code bases.

    Additional Information

    We are committed to an inclusive and diverse Twitter. Twitter is an equal opportunity employer. We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, age, disability, veteran, genetic information, marital status or any other legally protected status.

    San Francisco applicants: Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records

  • Industry
    Media Production