Dinasour Header Image
Two Barrels LLC Logo

Two Barrels LLC

Application Security Engineer

Posted 6 Hours Ago
Be an Early Applicant
Remote
Hybrid
Hiring Remotely in Brazos Country, TX
Mid level
Remote
Hybrid
Hiring Remotely in Brazos Country, TX
Mid level
As an Application Security Engineer, you will focus on identifying vulnerabilities in applications to enhance security. This entails using penetration testing tools, creating security reports, automating processes, and collaborating with security engineers. You will stay updated on security exploits and communicate findings to stakeholders.
The summary above was generated by AI

Overview:
Two Barrels is hiring an Application Security Engineer for $175,000/year. You will be a traditional company employee. This is a full time 40 hour/week position with company benefits. This is a remote position. Our main office is in Spokane WA, and we have satellite offices in Austin TX and Salt Lake City UT.
We are expanding our team to include an Application Security Engineer to be 100% focused on our security efforts. As the right candidate, you will have experience working in-house as a full-time penetration tester, a regular 3rd party bug bounty program pen tester, or in a similar security type role. Your job will be to identify our vulnerabilities to help keep our information safe and secure.
Location:
Remote | Spokane - Austin - SLC |
Duration:
Full Time
Wage:
Up to $175,000/year
Responsibilities:

  • Understand and safely use various open source penetration testing tools and when appropriate, emulating hacker tactics, techniques, procedures
  • Create security vulnerability reports for both technical and executive audiences
  • While in-between assessments, you will be expected to help our security engineers think through solutions to problems you find
  • Automate tasks and script at a basic level to enhance penetration testing processes
  • Passion for learning new technologies and processes, and contributing to refining existing capabilities
  • Communicate with stakeholders (technical and non-technical), both verbal and written
  • Stay up to date on 0 day exploits for tech stacks we use


Minimum Qualifications:

  • Solid fundamentals in webapp and network pentesting (2+ years). Pentesting experience in mobile apps, APIs, and/or cloud environments a bonus
  • 4+ years of professional experience in Ruby on Rails or equivalent and Vue or a Frontend equivalent framework
  • Experience with Linux and cloud environment testing
  • Understanding of security issues for desktop, virtual, cloud services and network infrastructures
  • Working knowledge of information systems security standards/practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling)
  • Experience with secure network protocols and encryption of communications between networked hosts
  • Experience in IT systems and security policies, standards, industry trends, and techniques
  • Experience with assessing APT threats, Penetration Testing, Vulnerability Management, attack methodologies, forensics analysis techniques, malware analysis, attack surface comprehension, Cyber Threat Emulation operations, Cyber Advanced Threat Emulation Team operations and research, identification, and/or verification of new APT TTPs
  • Fundamental understanding of security knowledge of testing mobile, native applications, web applications, distributed and database systems
  • Must be detail-oriented and possess strong problem-solving skills and ability to analyze for potential future issues
  • Solid understanding of common webapp vulnerabilities, exploitation techniques, and remediation options


Why you might like this job:
You've changed a price on a website you were checking out on to see if it worked. You've messed around where you shouldn't have and you've always thought it would be fun to do that full time in a way that didn't make you feel like an evil person or that karma would catch up to you. Maybe you've messed with folks in the past too much and want to earn some good karma points by helping us secure our high volume software and systems.
#BI-Remote
Benefits:

  • Great Wage & Success Meetings with your manager
  • Work From Home comfort package & company provided equipment
  • 22 days paid time off annually, PLUS 4 paid holidays
  • 4% 401k employer matching through Fidelity
  • 100% employer-paid medical, dental and vision for employees
  • Maternity and Paternity Leave
  • Flexible hours
  • Coffee shop next door
  • Crappy parking? Oh, I mean a cool downtown location for easy public transportation options...

Top Skills

Ruby

Similar Jobs at Two Barrels LLC

11 Days Ago
Remote
Hybrid
Brazos Country, TX, USA
Senior level
Senior level
eCommerce • Legal Tech • Professional Services • Software • Data Privacy
The Application Security Director at Two Barrels will lead the security team and engage in hands-on work. Responsibilities include creating security strategies, ensuring compliance, educating staff, and building a collaborative team environment. Candidates should be skilled in coding, particularly with Ruby, and have deep knowledge of security protocols in both infrastructure and application development.
Top Skills: Ruby
19 Days Ago
Remote
Hybrid
Brazos Country, TX, USA
Mid level
Mid level
eCommerce • Legal Tech • Professional Services • Software • Data Privacy
The Senior PPC Management Specialist at Two Barrels will launch and manage various PPC campaigns, set budgets, and generate reports while collaborating with writers, designers, and developers to ensure effective campaigns. The role emphasizes creativity and problem-solving in a budget-friendly environment.
Top Skills: Bing AdsGoogle AdsGoogle AnalyticsYahoo Ads
19 Days Ago
Remote
Hybrid
Brazos Country, TX, USA
Mid level
Mid level
eCommerce • Legal Tech • Professional Services • Software • Data Privacy
As a Cyber Security Analyst, you will protect computer networks by monitoring threats, analyzing vulnerabilities, performing security audits, and implementing risk management strategies. You'll also document breaches and recommend security improvements based on your research.
Top Skills: PythonRuby

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account