Company Name:
Company Url:
Short Pitch:
Description:
Headquarter Location:
Tags:


Job Url:

Sprout General Referrals




Sprout General Referrals is hiring a Remote Application Security Engineer

Description

Sprout Social is looking to hire an Application Security Engineer to the IT team.

Why join Sprout’s IT team?

Sprout’s Corporate IT team is a combination of adjacent squads working on projects under one umbrella. This unique structure is an exciting opportunity to grow your career in technology with exposure to projects all across our discipline—something you don’t see often in other organizations. It allows us to move quickly and collaborate with minimal friction or red tape. As a part of this team, you’re also given the space and encouraged to stretch beyond your core function, and make a deeper impact on the broader organization. In short, the work you do here matters, and you feel that day in and day out. 

What you’ll do

  • Conduct automated and manual testing of our web applications, micro-services, APIs, infrastructure, and other properties to identify vulnerabilities
  • Work with engineering teams to complete targeted reviews of new features at key points of the software development lifecycle
  • Work with development teams to transparently build security checks into the CI/CD pipeline
  • Oversee our bug bounty program. Set scope, triage submissions, coordinate escalations to engineering teams, and reward bounties. Cultivate relationships with the ethical hacker community.
  • Identify metrics that can help measure effectiveness of controls, gaps in coverage, need for head count, and trends in findings.
  • Effectively communicate with others in the organization about open security risks, contributing factors to and prioritization of those risks to collaboratively develop new security standards and reference architectures
  • Participate in a security on-call schedule and help support operational work related to your focus area
  • Establish yourself as a technical expert and foster a security-first culture through education, skill development, and implementation of effective processes and practices

What you’ll bring

These are the minimum qualifications that our hiring team is looking for in this role:

  • 3+ years of experience performing security assessments for a variety of systems, applications, APIs, and proprietary technology to secure cloud-based and containerized environments
  • Advanced knowledge and understanding in various disciplines: web application security, mobile app security, network security, operating system internals and hardening, applied cryptography, cloud computing. (You're expected to be an expert in at least one of these areas.)
  • Experience writing and maintaining code in at least one common programming language such as Python, Go, Javascript, etc and a desire to continue learning
  • Experience with manual and automated software testing, fuzzing, static/dynamic code analysis, and manual code reviews

Additionally, these are the preferred qualifications that would indicate a particularly strong candidate:

  • Experience leading “shift left” efforts to transparently build security into the software development lifecycle and implement pragmatic defenses
  • Familiarity with technology/tools such as Kubernetes, Docker, Jenkins, Terraform, AWS, Github, etc
  • Experience managing a vulnerability management program, performing documenting threat modeling processes, and an expert in determining the severity of a vulnerability to the business.
  • Strong verbal and written communication, and the ability to tailor your message to audiences across and beyond the organization
  • Have experience building security tools, scripts, and automation
  • Have familiarity with AI/ML security risks such as data poisoning, model extraction, adversarial examples, etc. and mitigations
  • Certifications such as GWAPT, eWPT/eWPTx, OSCP, OSWA, CISSP, or other relevant certifications are highly preferred.

How you’ll grow

Within 1 month, you will have:

  • Experienced Sprout’s in-depth onboarding, covering everything from our company mission and values, hearing directly from executives and founders, to deep training on our products and the value that Sprout delivers to our customers
  • Made a plan with your manager and colleagues to set initial priorities, align on expectations for your role, plant goalposts for your career, and learn about Sprout’s approach to security
  • Learned our existing tooling and begin monitoring the status of our environments
  • Begun collaborating regularly with teammates and get up to speed on our current and future initiatives
  • Begun receiving feedback on your approach to managing and engaging our existing risks and security capabilities

Within 3 months, you will have:

  • Have worked with teammates to create and prioritize team quarterly objectives and key results
  • Begun deconstructing larger security projects into smaller, more manageable deliverables
  • Started fully understanding the breadth and depth of technologies and tools under the team’s purview
  • Evaluated and triage alerts triggered from our monitoring platforms
  • Participate in Security on-call rotation
  • Build connections with members from other teams through active networking and community building to help foster a security-first culture

Within 6 months, you will have:

  • Measurably improved the security tooling and telemetry used at Sprout
  • Examples of security gaps identified within our systems, plans documented to mitigate identified risks, and work prioritized within various team’s workstreams
  • Improved upon internal and external security policies and standards
  • Created standard reports on security health and recommendations based on KRI and other measurable metrics
  • Completed your first semi-annual performance review with your manager, where you’ll discuss your accomplishments in your role and work together to build goals/objectives and personal key results for your professional growth

Within 12 months, you will have:

  • Become a go-to expert and application security representative within Sprout
  • Become a trusted partner in the creation of the security roadmap for future work
  • Effectively communicated with partners across the organization to ensure big-picture alignment and encourage cross-team collaboration
  • Surprise us! Use your unique ideas and abilities to change Sprout Security in beneficial ways that we haven’t considered yet

Of course, what is outlined above is the ideal timeline, but things may shift based on business needs and other projects and tasks could be added at the discretion of your manager.

Our Benefits Program

We’re proud to regularly be recognized for our team, product and culture. Our benefits program includes:

  • Insurance and benefit options that are built for both individuals and families
  • Progressive policies to support work/life balance, like our flexible paid time off and parental leave program 
  • High-quality and well-maintained equipment—your computer will never prevent you from doing your best
  • Wellness initiatives to ensure both health and mental well-being of our team
  • Ongoing education and development opportunities via our Grow@Sprout program and  employee-led diversity, equity and inclusion initiatives.
  • Growing corporate social responsibility program that is driven by the involvement and passion of our team members
  • Beautiful, convenient and state-of-the-art offices in Chicago’s Loop and downtown Seattle, for those who prefer an office setting

Whenever possible, Sprout wants to provide our team with the flexibility to work in the location that makes the most sense for them. Sprout maintains a remote workforce in many places in the United States. However, we are not set up in all states, so please look at the drop-down box in our application to see whether your state is listed. Few roles require an office setting. If your position requires a physical presence in a Sprout office, it will be evident in the job listing and your offer letter.

The base pay range for this role is $120,000 - $140,000 USD annually. Individual base pay is based on various factors, including relevant experience and skills, the responsibility of the role, and job duties/requirements. In addition to base pay, some Sales and Success roles can earn sales incentives. 

Sprout’s compensation ranges are intentionally broad to allow for our team members' growth within their role. These ranges were determined by a market-based compensation approach; we used data from trusted third-party compensation sources to set equitable, consistent and competitive ranges. We also evaluate compensation bi-annually, identify any changes in the market and make adjustments to our ranges and existing employee compensation as needed.

Base pay is only one element of an employee's total compensation at Sprout. Every Sprout team member has an opportunity to receive restricted stock units (RSUs) under Sprout’s equity plan. Employees (and their dependents) are covered by medical, dental, vision, basic life, accidental death, and dismemberment insurance, and Modern Health (a wellness benefit).  Employees are able to enroll in Sprout’s company’s 401k plan, in which Sprout will match 50% of your contributions up to 6% with a maximum contribution. Sprout offers “Flexible Paid Time Off” and ten paid holidays. We have outlined the various components to an employee’s full compensation package here to help you to understand our total rewards package.

Sprout Social is proud to be an Equal Opportunity Employer and an Affirmative Action Employer. We do not discriminate based on identity- race, color, religion, national origin or ancestry, sex (including sexual identity), age, physical or mental disability, pregnancy, veteran or military status, unfavorable discharge from military service, genetic information, sexual orientation, marital status, order of protection status, citizenship status, arrest record or expunged or sealed convictions, or any other legally recognized protected basis under federal, state, or local law. Learn more about our commitment to diversity, equity and inclusion in our latest DEI Report.

If you need a reasonable accommodation for any part of the employment process, please contact us by email at accommodations@sproutsocial.com and let us know the nature of your request and your contact information. We'll do all we can to ensure you're set up for success during our interview process while upholding your privacy, including requests for accommodation. Please note that only inquiries concerning a request for reasonable accommodation will be responded to from this email address.

For more information about our commitment to equal employment opportunity, please click here (1) Equal Opportunity Employment Poster (2) Sprout Social's Affirmative Action Statement (3) Pay Transparency Statement

When you apply for employment with Sprout Social, we will process your job applicant data, including your employment and education history, transcript, writing samples, and references as necessary to consider your job application for open positions. Your personal data will be shared with Greenhouse Software, Inc., and Crosschq, Inc., cloud services providers located in the United States of America and engaged by Sprout Social to help manage its recruitment and hiring process on Controller’s behalf. Accordingly, if you are located outside of the United States, by clicking “Submit Application” on this site, you consent to the transfer of your personal data to the United States. For more information about our privacy practices please visit our Privacy Policy. California residents have additional rights and should review the Additional Disclosures for California Residents section in our Privacy Policy.

Additionally, Sprout Social participates in the E-Verify program in certain locations, as required by law. 

#LI-REMOTE

See more jobs at Sprout General Referrals

Apply for this job

Sprout General Referrals is hiring a Remote Staff Software Engineer

Description

Sprout Social is looking to hire a Staff Software Engineer to join our Engineering  team.

Why join Sprout’s Engineering team?

With collaborative cross-functional teams that span mobile, front-end, back-end, QA and site reliability engineering—the Sprout Engineering team is a place to sharpen your craft and solve hard problems with the smartest people in the industry. You’ll get to work on a “tech-giant” scale with smaller, supportive teams where every engineer has the chance to make an impact on our company, and our customers. The best part? In our industry, you often have to switch jobs or even companies to learn a new part of a tech stack or business. But at Sprout, our product is a suite, so you just need to move teams. You’re able to diversify your skills, which not only benefits your team—but also your career. 

What you’ll do

  • You will help lead the team through complicated product and technical roadmaps and guide them to successful outcomes. 
  • You will work to improve the processes, systems, and tools we use to deliver quality products, champion ideas that matter, and hold the team accountable.

What you’ll bring

We’re looking for a creative, collaborative, pragmatic, highly motivated, and inquisitive technical leader to join our team in building great software. If you can solve hard problems, deliver quality server side software, and confidently guide your peers to learn from and teach each other, we’d love to talk with you!

The minimum qualifications for this role include:

  • 7+ years experience developing and supporting software in a production environment
  • 5+ years experience programming in object oriented languages such as Java, Python, or C++

Preferred qualifications for this role include:

  • 5+ years experience developing and supporting scalable, distributed backend services
  • 4+ years of working with databases

How you’ll grow

Within 1 month, you’ll plant your roots, including::

  • Complete Sprout’s New Hire training program alongside other new Sprout team members.
  • Get acclimated to the team's current Mission, Goals, and Objectives along with future product roadmaps.
  • Deploy and make changes to our production systems.
  • Interact with SQL or NoSQL data stores and NSQ messaging queues.
  • Collaborate regularly with product managers, QA engineers, and other product teams to deliver value to our users.
  • Get regular team feedback on your work through code reviews and pairing.
  • Proactively monitor the health of our services in production to ensure our customers always have a world-class experience

Within 3 months, you will:

  • Decompose work into small, similarly sized units so that estimation is unnecessary.
  • Work with your squad to create and prioritize quarterly team goals.
  • Contribute to our Agile culture of continuous improvement through retrospective meetings and experimentation-oriented thinking.
  • Build connections with members from other teams through guild meetings and chapter outings.
  • Participate in technical design meetings with your teammates to walk through new feature ideas. 
  • Work with product managers, UX developers, and front-end engineers to come up with the MVPs of new features.
  • Be the first line of defense against product outages and bugs while on support duty.
  • Maintain, scale, and build upon systems that handle hundreds of thousands of messages a day. 
  • Write design documents, coordinate dependencies, and act as the domain owner for new projects.

Within 6 months, you will:

  • Integrate and use monitoring and alerting tools to know about problems before our users.
  • Create and manage concurrent, distributed systems.
  • Build your engineering skills by attending in-house presentations, workshops, and training sessions.
  • Lead technical design meetings with your teammates to walk through new feature ideas. 
  • Identify technical debt and performance bottlenecks within our systems, come up with a plan to improve the code, and get it pushed to production.
  • Work and communicate effectively with other groups across the organization to ensure big-picture alignment and encourage cross-team collaboration.
  • Form a career growth plan with your manager and work towards it.
  • Partner with the Infrastructure team to improve your team’s ability to deliver reliable, highly available services.

Within 12 months, you will:

  • Be the go-to expert of your teams’ systems at the company.
  • Own cross-organizational projects, demonstrating project management skills, consensus building, and strong leadership.
  • Actively mitigate risk of failed delivery and missed deadlines through courageous, transparent communication with colleagues and stakeholders throughout a project life cycle.
  • Lead technical architecture meetings. 
  • Identify technical debt and performance bottlenecks within our systems, come up with a plan to improve the code, and get it pushed to production.
  • Mentor junior engineers, helping them level up technically.
  • Build connections with members from other teams through active networking and community building.
  • Have opportunities to contribute to in-house technical presentations and workshops that share your expertise with large groups of Sprout engineers.
  • Surprise us! Use your unique ideas and abilities to change your team in beneficial ways that we haven’t even considered yet.

Of course, what is outlined above is the ideal timeline, but things may shift based on business needs and other projects and tasks could be added at the discretion of your manager.

Our Benefits Program

We’re proud to regularly be recognized for our team, product and culture. Our benefits program includes:

  • Insurance and benefit options that are built for both individuals and families
  • Progressive policies to support work/life balance, like our flexible paid time off and parental leave program 
  • High-quality and well-maintained equipment—your computer will never prevent you from doing your best
  • Wellness initiatives to ensure both health and mental well-being of our team
  • Ongoing education and development opportunities via our Grow@Sprout program and  employee-led diversity, equity and inclusion initiatives.
  • Growing corporate social responsibility program that is driven by the involvement and passion of our team members
  • Beautiful, convenient and state-of-the-art offices in Chicago’s Loop and downtown Seattle, for those who prefer an office setting

Individual base pay is based on various factors, including work location, relevant experience and skills, the responsibility of the role, and job duties/requirements. In the United States, we have two geographic pay zones. You can confirm the pay zone for your specific location with your recruiter during your interview process. For this role, our current base pay ranges for new hires in each zone are:

  • Zone 1: $190,000 to $235,000 USD annually
  • Zone 2: $180,000 to $220,000 USD annually

Sprout’s compensation ranges are intentionally broad to allow for our team members' growth within their role. These ranges were determined by a market-based compensation approach; we used data from trusted third-party compensation sources to set equitable, consistent, and competitive ranges. We also evaluate compensation bi-annually, identify any changes in the market and make adjustments to our ranges and existing employee compensation as needed.

Reach out to Hubertine Henzler for more information.

 

See more jobs at Sprout General Referrals

Apply for this job