Adult, Female, Person, Woman, Wristwatch, Male, Man, Laptop, Glasses, Student

linked      instag       twitte

Senior Software Engineer II, Application Security

  • Brooklyn
  • Full-time

Company Description
Etsy is the global marketplace for unique and creative goods. We build, power, and evolve the tools and
technologies that connect millions of entrepreneurs with millions of buyers around the world. As an Etsy
Inc. employee, whether a team member of Etsy, Reverb, or Depop, you will tackle unique, meaningful, and
large-scale problems alongside passionate coworkers, all the while making a rewarding impact and
Keeping Commerce Human.

Salary Range:

$175,000.00 - $205,000.00

What’s the role?

Etsy is seeking a Senior Security Engineer to join our Application Security team. As part of the larger Security and Privacy Engineering org, we help product teams build secure software and develop and maintain security critical parts of our web application. We do this by partnering at the design stage for larger features, reviewing code, developing threat models, performing pentests, and leading security initiatives.

This role is focused on the security assessments part of the program. In it, you’ll be tasked with discovering impactful vulnerabilities that can’t be found with off-the-shelf tools or scanners. It will require you to develop in depth threat models and dive deep into our tech stack and code bases. You’ll work with engineering teams to develop mitigation strategies for the vulnerabilities you discover, and we will also rely on your expertise to provide security feedback to new project and service proposals.

This is a full-time position reporting to the Engineering Manager - Application Security. In addition to salary, you will also be eligible for an equity package, an annual performance bonus, and competitive benefits that support you and your family as part of your total rewards package at Etsy.

For this role, we are considering candidates based in the United States. Candidates living within commutable distance of Etsy’s Brooklyn Office Hub or in the San Francisco Bay Area may be the first to be considered. For candidates within commutable distance, Etsy requires in-office attendance once or twice per week depending on your proximity to the office. Etsy offers different work modes to meet the variety of needs and preferences of our team. Learn more details about our work modes and workplace safety policies here.

What’s this team like at Etsy?

At Etsy, we believe that code is craft, and that the work we do is part of a larger creative culture represented by the artists and designers who make Etsy such a unique marketplace. We believe that small, empowered, self-motivated teams can do big things. We measure and test our work, take advantage of our pioneering continuous deployment system, and cultivate a blameless culture based on trust and a commitment to learning. Learn more about our engineering philosophies, tools, and some of the challenges we’ve been solving on our Engineering blog: http://codeascraft.com/

What does the day-to-day look like?

  • Mentor other application security engineers
  • Lead threat modeling exercises
  • Select penetst targets and lead pentest
  • Guide teams through remediation discussions
  • Research new attack vectors and technologies
  • Develop proof of concept exploits for novel findings
  • Perform security focused code reviews
  • Support development teams during the design phase of development
  • Identify opportunities where we can address classes of vulnerabilities or areas of risk
  • Of course, this is just a sample of the kinds of work this role will require! You should assume that your role will encompass other tasks, too, and that your job duties and responsibilities may change from time to time at Etsy's discretion, or otherwise applicable with local law.

Qualities that will help you thrive in this role are:

  • 5+ years of experience in manual penetration testing
  • Deep appsec expertise
  • Excellent written communication
  • Experience in professional software development
  • Application security subject matter expertise, including
    • Web application security
    • Mobile application security
    • Authentication/Authorization
    • Cryptography
  • Experience threat modeling large-scale distributed systems
  • Experience with security architecture and security by design
  • Track record of contributing to public bug bounties and CVEs a strong plus
  • Experience with finding vulnerabilities in PHP codebases a plus

Additional Information

What's Next
If you're interested in joining the team at Etsy, please share your resume with us and feel free to include a
cover letter if you'd like. As we hope you've seen already, Etsy is a place that values individuality and
variety. We don't want you to be like everyone else -- we want you to be like you! So tell us what you're all
about.

Our Promise
At Etsy, we believe that a diverse, equitable and inclusive workplace furthers relevance, resilience, and
longevity. We encourage people from all backgrounds, ages, abilities, and experiences to apply. Etsy is
proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to
equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual
orientation, age, citizenship, marital status, disability, gender identity or Veteran status. If, due to a
disability, you need an accommodation during any part of the interview process, please let your recruiter
know. While Etsy supports visa sponsorship, sponsorship opportunities may be limited to certain roles
and skills.

Ready to Apply?

Autofill my information with LinkedIn
Alert me about jobs like this

Not You?

Thank you

Remind you of someone else?

Share this opportunity.

Not You?

We'll send you both an email!

Let’s keep in touch!

We’ll share #LifeAtEtsy updates catered to your location and experience.

We also encourage you to sign up for job alerts.

Autofill my information with LinkedIn

Not You?

Thank you

Ready to Apply?

Autofill my information with LinkedIn
Alert me about jobs like this

Not You?

Thank you

Not the right fit? Check out these other jobs!

Software Engineering Manager

Etsy, Inc. JR3436 Portland Oregon United States Portland, Oregon, United States Software Engineer Full-time M3
Company Description Etsy is the global marketplace for unique and creative goods. We build, power, and evolve the tools and technologies that connect millions of entrepreneurs with millions of buyers around the world. As an Etsy Inc. employee, whe...

Engineering Manager, Experimentation Observability

Etsy, Inc. JR3439 New York New York United States New York, United States Data Science & Machine Learning Full-time M3
Company Description Etsy is the global marketplace for unique and creative goods. We build, power, and evolve the tools and technologies that connect millions of entrepreneurs with millions of buyers around the world. As an Etsy Inc. employee, whe...

Engineering Manager, Experimentation Configuration

Etsy, Inc. JR3443 New York New York United States New York, United States Data Science & Machine Learning Full-time M3
Company Description Etsy is the global marketplace for unique and creative goods. We build, power, and evolve the tools and technologies that connect millions of entrepreneurs with millions of buyers around the world. As an Etsy Inc. employee, whe...

Senior Data Scientist, Product Analytics

Etsy, Inc. JR3447 CDMX Mexico CDMX, Mexico Analytics Full-time IC3
Company Description Etsy is the global marketplace for unique and creative goods. We build, power, and evolve the tools and technologies that connect millions of entrepreneurs with millions of buyers around the world. As an Etsy Inc. employee, whe...

Data Scientist, Product Analytics

Etsy, Inc. JR3461 New York New York United States New York, United States Analytics Full-time IC2
Company Description Etsy is the global marketplace for unique and creative goods. We build, power, and evolve the tools and technologies that connect millions of entrepreneurs with millions of buyers around the world. As an Etsy Inc. employee, whe...
Join Our Talent Community