Senior Application Security Engineer

πŸ’° $157k-$230k

Job description

At GFiber, we believe that great internet has the power to drive innovation, strengthen communities, enable the impossible, and do all the everyday things that make all of our world go round. And the job of creating better internet is never done - so we’re growing! Our team is committed to building a place where people who want to make a difference can grow their careers and find their spot to belong.

GFiber is an Alphabet company that brings Google Fiber and Google Fiber Webpass internet services to homes and businesses across the United States. Our teams are expanding as we connect more cities and people to exceptional internet.

The application window will be open until at least August 15, 2025. This opportunity will remain online based on business needs which may be before or after the specified date.

The Cybersecurity team at GFiber leads the protection of our networks, systems, and data from advanced threats. We champion the effort to ensure GFiber delivers internet services securely, embedding security into the core of our offerings and making the secure path the default path for our developers and customers. This Senior Application Security Engineer position is a key role within the Cybersecurity team, dedicated to proactively integrating security throughout the software development lifecycle (SDLC). This role will be at the forefront of designing, building, and deploying secure applications, ensuring the resilience and trustworthiness of GFiber’s services, and will be critical in maturing our application security program and fostering a security-first engineering culture.

Role Description

As a Senior Application Security Engineer, your mission is to ensure GFiber develops and delivers secure services and applications to our customers. You will achieve this by embedding security best practices, tools, and knowledge directly into our development processes and teams. You’ll leverage your deep expertise in application security, secure coding practices, threat modeling, and automated security testing to empower our engineering teams. Your work will enhance our ability to design, build, and deploy secure applications effectively from the ground up. In this role, you’ll be a pivotal member of the Cybersecurity team, directly shaping GFiber’s application security posture. You will focus on building and improving our secure development lifecycle, leveraging automation, and providing expert guidance to development teams. You’ll collaborate closely with Software Engineering, DevOps, Product Management, and other Cybersecurity functions (like Security Operations and GRC) to ensure a holistic approach to security.

In this role, you’ll:

  • Champion Secure by Design Principles: Lead the integration of security into all phases of the software development lifecycle (SDLC), from design and threat modeling to secure coding, testing, and deployment, ensuring the “default path” is the secure path for application development.
  • Lead Application Security Initiatives: Drive key projects to enhance GFiber’s application security posture, including the development of security standards, secure coding guidelines, and the implementation of advanced security testing methodologies.
  • Drive Automation and Tooling: Design, implement, and optimize automated security tools (SAST, DAST, SCA, IAST) and integrate them into CI/CD pipelines to provide rapid feedback to developers and accelerate secure software delivery.
  • Evolve Threat Modeling and Security Reviews: Establish and lead threat modeling efforts for new and existing applications, conduct in-depth security architecture reviews, and perform manual and automated code reviews to identify and mitigate vulnerabilities.

At a minimum we’d like you to have:

  • Bachelor’s degree in Computer Science, Information Security, a related field, or equivalent practical experience.
  • 7 years of experience in application security, including hands-on experience with secure SDLC practices, threat modeling, vulnerability assessment, and penetration testing.
  • Direct experience with one or more programming languages (e.g., Java, JavaScript, Kotlin) and experience with code review.
  • Experience with application security tools and technologies (e.g., SAST, DAST, IAST, SCA, WAF).

It’s preferred if you have:

  • Demonstrated success in developing, implementing, and maturing an application security program or significant security features.
  • Experience building and deploying security solutions in GCP (Google Cloud Platform).
  • A deep understanding of common application vulnerabilities (e.g., OWASP Top 10, SANS Top 25), attack vectors, and remediation techniques.
  • Experience in developing and delivering security training and awareness programs to engineering teams.
  • Relevant security certifications (e.g., GPEN, CSSLP, GWAPT, GWEB, OSCP, OSWE, OSEP).
  • Experience with container security (Docker, Kubernetes) and Infrastructure as Code (IaC) security principles.

The US base salary range for this full-time position is between $157,000 - $230,000 + bonus + cash award + benefits. As pay varies by location, your recruiter will share more about the specific salary range for your targeted location during the hiring process.

GFiber is committed to equal opportunity employment regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, citizenship, marital status, disability or Veteran status. Disclosure is voluntary, and this information will be kept confidential in compliance with Google’s Candidate Privacy Policy. For more information please refer to our Equal Employment Opportunity Policy and theΒ EEOC’s “Know your rights: workplace discrimination is illegal” (PDF).

It’s important to us to create an accessible, inclusive workplace for everyone. If you have a need that requires accommodation, please let us know by completing ouraccommodations for applicants form. Our candidate accommodations team will then connect with you to confidentially discuss your options.

Share this job:
Please let Google Fiber know you found this job on Remote First Jobs πŸ™

Similar Remote Jobs

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service πŸ™

Apply