Senior Security Engineer

Change.org
11dRemote

About The Position

Change.org is searching for a Senior Security Engineer to help secure our global infrastructure and applications. You will report to the Senior Director of Engineering, Technical Operations and as a key member of our engineering team you will be responsible for tasks involving vulnerability management, vendor security review, and the further automation of our security tooling. We’re a social impact business (a public benefit company), and the world's largest social change platform with 100 million users, 40,000+ campaigns launched on the site every month, and a 100% user-generated revenue model. Our users win campaigns for change once every hour. We’re working for a world where no one is powerless, and where creating change is a part of everyday life. We’re just getting started and hope you’ll join us! From mobilizing over 5 million people to investigate the fires in the Amazon, to mobilizing nearly 3 million against war and famine in Yemen, to large-scale mobilizations for the people of Iran and against the war in Ukraine, and calling for Racial Justice in the US, many movements were born on Change.org. Dozens of local, national, and international victories are happening every day thanks to the strength of our members who are changing the lives of people around the world. We want to help them go even further and we need your help!

Requirements

  • Strong grasp of web application security fundamentals.
  • Proficiency in Python or similar for scripting, automation, and integrating security tools.
  • Experience with security scanning tools and pipeline automation.
  • Working knowledge of AWS and Kubernetes from an application security perspective.
  • Ability to clearly communicate risks and collaborate effectively with development teams.
  • 4–6 years in application or cloud security, or as a software engineer with security responsibilities.
  • Proven track record of hands-on vulnerability remediation and practical risk reduction.

Nice To Haves

  • Exposure to secure SDLC practices and common modern stacks (bonus: Elixir, Node, Ruby).
  • Experience building or tuning security automation that improves developer productivity and reduces false positives.

Responsibilities

  • Identify, triage, and drive remediation of vulnerabilities across Change.org’s applications and APIs.
  • Integrate and maintain automated security checks in CI/CD .
  • Partner with developers on secure design and code reviews for high-impact features.
  • Strengthen AWS and Kubernetes app-layer security.
  • Contribute to incident response when product or code-related vulnerabilities are involved.
  • Participate in our on call rotation
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service