Yext - New York, NY

posted 3 months ago

Full-time - Mid Level
New York, NY
Professional, Scientific, and Technical Services

About the position

Yext is seeking a Senior Application Security Engineer to join our Security Office. This role is pivotal in ensuring the security and integrity of our product and software platform. As a technical subject matter expert, you will focus on key areas such as threat modeling, secure code review, penetration testing, and post-deployment security monitoring. Your expertise will empower product and engineering teams to make informed security and privacy decisions through comprehensive reviews, assessments, and offensive security exercises. Additionally, you will play a crucial role in fostering a culture of security awareness and compliance within Yext, working closely with the Application Security leader to drive initiatives that enhance our security posture. In this position, you will design and implement security practices and standards across our product and application environments. You will be responsible for threat modeling systems and applications, conducting security reviews, and performing detailed penetration tests on both web and mobile infrastructures. Identifying security risks and developing effective mitigation strategies will be a key part of your responsibilities. You will also develop tooling and automation to facilitate continuous testing and increase the coverage of penetration tests and other security assessments. Furthermore, you will provide guidance on secure coding practices based on industry standards such as the OWASP Top 10 and CIS Controls, and contribute to the creation and delivery of security training for internal teams. Your role will also involve assisting in the analysis and response to bug bounty programs, ensuring that Yext maintains a robust security framework.

Responsibilities

  • Design and implement security practices and standards across product and application environments
  • Threat modeling systems and applications and performing security reviews
  • Perform detailed penetration tests of web and mobile infrastructure
  • Identify security risks and develop mitigation strategies
  • Develop tooling and automation to facilitate continual testing and increase coverage of penetration tests and other security assessments
  • Develop system design and software best practices for engineering teams
  • Provide guidance for secure coding practices and proactive controls based on OWASP Top 10 and CIS Controls
  • Contribute to the creation of security training and delivery to internal teams
  • Assist in the analysis and response to bug bounty programs

Requirements

  • Bachelor's Degree in Information Technology or related field of study
  • 5 - 7 years of relevant work experience in Development or Security Engineering teams
  • Experience in software development, ability to guide and mentor a technical engineering team in coding and scripting best practices
  • Good understanding of modern application security frameworks and offensive security toolkits
  • Self-motivated team player that is energetic, with excellent interpersonal and organizational skills
  • Strong leadership and negotiation skills with technical groups
  • Experience presenting to development and architecture teams on security recommendations
  • Strong problem-solving, critical thinking and analytical skills

Benefits

  • Medical, dental and vision benefits
  • Life insurance
  • Short term and long-term disability
  • 401(k) retirement plan
  • Vacation and sick leave
  • Equity (stock) based compensation and/or variable pay programs based on performance relative to goals and targets
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service