Security Engineer, Bitly

DevSecOps

$105.6-158.4k

Plus stock options

AWS
GCP
JavaScript
Bash
Go
Terraform
Junior, Mid and Senior level
Remote in US

More information about location

Bitly

URL shortener tool

Open for applications

Bitly

URL shortener tool

201-500 employees

B2BInternal toolsSaaS

Open for applications

$105.6-158.4k

Plus stock options

AWS
GCP
JavaScript
Bash
Go
Terraform
Junior, Mid and Senior level
Remote in US

More information about location

201-500 employees

B2BInternal toolsSaaS

Company mission

Bitly's mission is to help businesses to grow and protect their brands by fostering deeper connections with users on the internet. It allows client companies to shorten their URLs, providing trusted and concise call-to-action links while using analytics and insights to maximise their marketing campaigns.

Role

Who you are

  • The ideal candidate will be passionate about cybersecurity and possess a strong technical background in application and cloud network technologies
  • An expert in application and cloud security with a deep understanding of the latest threats, vulnerabilities, and best practices
  • A cybersecurity enthusiast with a substantial technical foundation and a drive to stay ahead of emerging threats
  • Proficiency in programming and automation using Go, JavaScript, Bash, and Terraform
  • A collaborative team player who can effectively communicate and work with cross-functional teams to integrate security into every phase of the software development lifecycle and convey technical concepts to non-technical stakeholders
  • A problem-solver with a keen eye for detail and a proactive approach to identifying and addressing security vulnerabilities
  • A continuous learner who thrives in a fast-paced environment and is eager to stay updated on emerging technologies and trends in cybersecurity
  • Strong understanding of web application security principles, including OWASP Top 10 vulnerabilities and secure coding practices
  • Familiarity with both AWS and GCP production environments
  • Experienced in applying security best practices to meet industry compliance standards (e.g., SOC 2, PCI-DSS, HIPAA)
  • (Bonus) Security certifications such as CISSP, CSSLP, CEH, or GCP Professional Cloud Security Engineer / AWS Certified Security Engineer

What the job involves

  • We are seeking a talented and proactive Security Engineer to join our team
  • In this role, you will collaborate closely with our application production engineering teams and the Infosec team to integrate security best practices into all aspects of our software development lifecycle
  • Partner with rest of the InfoSec Team, IT and the Product-Engineering teams to implement the strategic security vision into our products
  • Design, implement, and maintain robust security architectures for our applications and cloud infrastructure to ensure our systems' confidentiality, integrity, and availability
  • Help implement Cloud Security Best Practices by configuring and managing security controls for cloud environments, including identity and access management (IAM), network security groups (NSGs), and encryption mechanisms
  • Keep detailed documentation of security configurations, policies, procedures, and incidents to help keep track of the status of security initiatives and compliance efforts
  • Implement security automation and orchestration workflows to streamline security operations and improve incident response times
  • Perform security-focused code reviews
  • Assist the InfoSec team in supporting the development and implementation of controls to achieve and maintain compliance with SOC 2 and other relevant industry standards
  • Support and consult with product engineering teams in the area of application security, including threat modeling and appsec reviews
  • Work closely with product engineering teams to embed security frameworks and security best practices throughout the software development lifecycle, including secure coding guidelines, static and dynamic code analysis, and dependency scanning
  • Participate in the entire software development lifecycle (SDLC), including threat modeling, secure code reviews, and security testing
  • Assist teams in reproducing, triaging, and addressing application security vulnerabilities
  • Take the lead in incident response efforts during security breaches or incidents, managing investigation, containment, eradication, and recovery activities while implementing preventative measures for the future

Our take

Bitly provides the service of shortening URLs along with offering link management for companies. Many major companies utilize shorter URLs for branding reasons; for example, Pepsi uses pep.si.

Shortened URLs have become big business, and competition in the space comes from the likes of TinyURL, along with Rebrandly and BL.INK. Bitly, that was majority purchased by Spectrum Equity for $63 million in 2017, has raised massive amounts of funding and achieved impressive annual revenues, and certainly seems to have established itself as a credible business in the market.

After acquiring leading QR code platform Egoditor and its flagship site QR Code Generator in 2021, Bitly has embarked upon rapid expansion, and added to the pool of talent across the business. For now, the company's focus seems to be on growing its global SaaS footprint; targeting QR Codes, link-in-bio, and link management.

Freddie headshot

Freddie

Company Specialist

Insights

Top investors

Few candidates hear
back within 2 weeks

13% employee growth in 12 months

Company

Funding (last 2 of 5 rounds)

Jul 2012

$15m

SERIES C

Oct 2010

$10m

SERIES B

Total funding: $30m

Company benefits

  • Stock Options
  • Comprehensive and competitive medical, dental, and vision insurance (all LGBT friendly)
  • 401k with up to 4% employer match
  • One Medical membership: Doctors you can text, call or email 24/7 and receive access to expert insurance guidance
  • Wellness reimbursement program
  • Partial cell phone service reimbursement
  • Voluntary LegalShield for legal services and IDShield for identity theft protection
  • Unlimited vacation, personal time, and flexible work from home policies
  • Remote options & work from home stipend
  • Generous parental leave policies; maternity and parental leave for growing families
  • Budget for professional development opportunities, including courses and conference attendance
  • Snacks, drinks, and weekly catered lunches
  • Company sponsored volunteering opportunities

Company values

  • Customer First - We are fiercely committed to our customers’ success. Our job is to ensure that our trusted platform, performance, and people help customers achieve their goals.
  • Growth Focused - We are building a fast-growing, healthy business powered by quick learning, constant optimisation, and data-driven decisions.
  • R.E.S.P.E.C.T - We are a team that respects each other and values diversity and inclusion. We treat others as we’d want to be treated and uphold the highest levels of integrity in everything we do.
  • >(!=) - We are driven to win, bring our “A Game” to work each day, and deliver exceptional results..
  • Do or Do Not, There is No Try - We say what we are going to do, and we do it.

Company HQ

Flatiron District, New York, NY

Founders

Toby Gabriner

(CEO, not founder)

Was an Investor and Board Member at both Improvado and Popwallet. Former CEO of NextRoll, Inc.

Share this job

View 9 more jobs at Bitly