Staff Application Security Engineer, Ironclad

$190-210k

+ Equity; Salary applicable to candidates based at SF headquarters only and may vary by other locations

AWS
Kubernetes
TypeScript
GCP
Python
Java
Ruby
Terraform
ELK
Azure
Prometheus
Grafana
Git
Datadog
Mid and Senior level
Remote in US
San Francisco Bay Area
Ironclad

Enterprise software for managing contracts

Be an early applicant

Ironclad

Enterprise software for managing contracts

501-1000 employees

B2BArtificial IntelligenceEnterpriseLegalMachine LearningSaaS

Be an early applicant

$190-210k

+ Equity; Salary applicable to candidates based at SF headquarters only and may vary by other locations

AWS
Kubernetes
TypeScript
GCP
Python
Java
Ruby
Terraform
ELK
Azure
Prometheus
Grafana
Git
Datadog
Mid and Senior level
Remote in US
San Francisco Bay Area

501-1000 employees

B2BArtificial IntelligenceEnterpriseLegalMachine LearningSaaS

Company mission

To power the world’s contracts.

Role

Who you are

  • Ironclad is seeking a skilled Application Security Engineer with a passion for securing modern software platforms and protecting sensitive data
  • We are looking for someone with strong experience in automated vulnerability scanning and penetration testing to strengthen our application security program
  • The ideal candidate will have experience in software development or testing at SaaS companies or in regulated fields
  • BA/BS/MS in Computer Science or related field or equivalent experience
  • 3+ Years of experience working in application security or software development, preferably with SaaS companies or in regulated fields
  • In-depth knowledge of application security concepts and practices, including OWASP Top 10 and SANS Top 25
  • Experience with SAST and SCA tools such as Snyk, Checkmarx, Veracode, WhiteSource, or Black Duck
  • Experience with security testing tools such as Burp Suite, AppScan, and Nessus
  • Experience with SOC 2, ISO 27001, NIST, and CIS standards and frameworks
  • Experience operating in any cloud provider (AWS, GCP, Azure, Digital Ocean etc.)
  • Ability to appropriately prioritize and respond to different escalations
  • Experience working collaboratively with cross-functional teams
  • Strong desire to take ownership of problems
  • Comfort working in a rapidly evolving environment and dealing with ambiguity
  • Excellent communication, analytical and problem-solving skills
  • Team and goal-oriented
  • High output, low ego

Desirable

  • Strong proficiency in scripting and any programming languages (TypeScript, Java, Python, Ruby etc.)
  • Experience with git and software branching and workflow strategies
  • Experience working with modern, microservice architectures including in Kubernetes or other containerized environments
  • Experience with enterprise observability platforms such as ELK, Datadog, Prometheus, Grafana, etc
  • Knowledge of Terraform or other infrastructure-as-code and configuration management solutions

What the job involves

  • This role will be responsible for conducting security assessments, identifying and mitigating risks, and implementing security best practices and process improvements across Ironclad’s Product, Platform and Engineering teams
  • Develop and implement secure coding practices, procedures, and standards for software development teams
  • Conduct application security assessments and vulnerability testing to identify and mitigate risks
  • Perform security reviews of code changes and ensure that security issues are addressed
  • Collaborate with cross-functional teams to remediate software vulnerabilities and implement secure coding practices
  • Integrate security review processes into Ironclad’s CI/CD pipeline
  • Conduct threat modeling and risk analysis to protect sensitive data
  • Provide domain expertise on protective controls including system, network, encryption, and authentication services
  • Work closely with members of the SRE, Development, IT, and Security teams to drive impactful changes to Ironclad’s cybersecurity posture
  • Work closely with the risk and governance teams to implement compliance and security requirements
  • Contribute to secure coding and other cybersecurity training programs
  • Stay up-to-date with the latest security trends, vulnerabilities, and attack techniques
  • Provide technical leadership and mentorship to other members of the engineering and security teams

Our take

Business contracting is often inefficient and messy, with approvals required from various stakeholders and many processes still paper-based. Ironclad is a platform that digitises, automates, and streamlines contract workflows, allowing legal teams to focus on legal work rather than paperwork. Ironclad’s platform features collaborative tools that facilitate business operations and extract and catalog contract metadata, making information easier to access and act upon. Its enterprise customers include Dropbox, Mastercard, Pixar, Fox, and L’Oréal.

Despite its success, Ironclad faces competition in the $3 billion contract lifecycle management industry from major players like DocuSign and emerging ones like Contractbook. The company recently announced Ironclad Signature, marking its entry into the $25 billion eSignature market. The new feature speeds up the signature process by an estimated 80% and provides summaries and approval histories to users. This new tool is expected to strengthen Ironclad's position in the sell-side contract lifecycle management market.

Additionally, Ironclad introduced value-based pricing, charging only for completed, signed agreements, unlike other providers who charge for every signature packet sent out. Ironclad, backed by investors like Accel, Sequoia, Y Combinator, and BOND, remains committed to innovating and maintaining its leadership in the contract lifecycle management space.

Kirsty headshot

Kirsty

Company Specialist

Insights

Top investors

Some candidates hear
back within 2 weeks

-3% employee growth in 12 months

Company

Funding (last 2 of 7 rounds)

Jan 2022

$150m

SERIES E

Dec 2020

$100m

SERIES D

Total funding: $334.1m

Company benefits

  • Dental, and vision insurance
  • 401K
  • Wellness reimbursement
  • Flexible vacation policy
  • Generous parental leave for both primary and secondary caregivers
  • Work from home opportunities
  • Health insurance

Company values

  • Intent
  • Empathy
  • Drive
  • Integrity

Company HQ

South Beach, San Francisco, CA

Leadership

Cai GoGwilt

(CTO & Chief Architect)

Studied HSPS at Cambridge, and Computer Science at MIT. Was a Summer Technology Analayst at Goldman Sachs. Worked as a Research Assistant at MIT. Was a Software Engineer at Palantir.

Former Corporate Lawyer at Fenwick and Professor of Law at the University of Notre Dame before founding Ironclad in 2014.

Salary benchmarks

We don't have enough data yet to provide salary benchmarks for this role.

Submit your salary to help other candidates with crowdsourced salary estimates.

Share this job

View 14 more jobs at Ironclad