Talent.com
No longer accepting applications
Application Security Engineer - Threat Modeling & Risk / Privacy AlignmentUtah | Hybrid

Application Security Engineer - Threat Modeling & Risk / Privacy AlignmentUtah | Hybrid

BambooHRLehi, UT, US
30+ days ago
Job type
  • Full-time
Job description

Application Security Engineer

This is a Utah-based hybrid position which will require some regular in-office days each week. Additionally, employment with BambooHR is contingent on passing both a background and credit check.

Essential Job Duties

We are expanding our security team and seeking a highly experienced and strategic Application Security Engineer with a deep understanding of threat modeling, risk assessment, and cross-functional collaboration. In this critical role, you will be responsible for proactively identifying and mitigating security risks by conducting thorough threat modeling, aligning security efforts with business objectives, and ensuring our platform meets the highest standards of security and privacy, particularly for a multi-tenant SaaS environment.

You will :

  • Threat Modeling Leadership : Lead and facilitate formal threat modeling exercises (e.g., STRIDE, LINDDUN, Attack Trees) for new and existing features, APIs, data flows, and architectural designs, translating technical risks into actionable insights.
  • Risk & Privacy Alignment : Act as a key liaison between engineering, product, legal, and privacy teams, effectively translating technical security risks into business terms and collaborating to find balanced solutions that meet both security and product goals.
  • Authentication & Authorization Expertise : Provide deep expertise and guidance on secure authentication mechanisms, session management, and complex access control models relevant to a multi-tenant SaaS platform.
  • Product Security Collaboration : Partner closely with product managers and engineering teams to embed security requirements early in the product development lifecycle, balancing user experience (UX) with robust security.
  • SaaS-Specific Security : Address security challenges unique to a SaaS environment, including multi-tenancy isolation, secure API design principles, prevention of horizontal privilege escalation, and secure data handling.
  • API Security Testing : Conduct hands-on security testing of APIs using various tools (e.g., Burp Suite, Postman, custom scripts) to identify vulnerabilities and ensure secure communication and data exchange.
  • Security Requirements : Define and document detailed security requirements and controls for new features and system enhancements.
  • Security Consultation : Provide expert security consultation and guidance to development teams on secure coding practices, architectural patterns, and vulnerability remediation.
  • Continuous Improvement : Stay current with the latest security threats, industry best practices, and emerging technologies, advocating for their adoption to enhance our platform's security posture.

What You Need to Get the Job Done

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • Minimum 3 years of specific, hands-on experience in Application Security.
  • AI and Automation-first mindset.
  • Deep understanding of web application and API security principles, including authentication, authorization (OAuth, OpenID Connect, JWT), session management, and access control models.
  • Demonstrated ability to translate technical security risks into clear, concise business terms for diverse audiences, including legal, privacy, and product stakeholders.
  • Experience collaborating directly with product teams to integrate security into product roadmaps and balance security with user experience.
  • Strong knowledge of common web application vulnerabilities (OWASP Top 10).
  • Excellent communication, interpersonal, and presentation skills.
  • What Will Make Us REALLY Love You

  • Relevant security certifications (e.g., CSSLP, GCSA, CISSP).
  • Experience with privacy frameworks and regulations (e.g., GDPR, CCPA).
  • Familiarity with cloud security architecture (AWS, Azure, GCP).
  • Experience with security champions programs.
  • What You'll Love About Us

  • A great company culture that has been recognized by multiple organizations like Inc, and Salt Lake Tribune
  • Comprehensive health, life, and disability insurance
  • Generous leave policies that include 4 weeks of vacation, 12 company holidays, parental leave, and volunteer time off so you can enjoy quality of life
  • 401k plans with up to 6% company match
  • $2000 Paid-Paid Vacation bonus
  • EAP through Headspace
  • Check out all our benefits that benefit you
  • About Us

    At BambooHR, we're building something different : we're building a people intelligence platform that transforms HR and sets people free to do great work! We're a proven market leader driving innovation while building lasting success through thoughtful, sustainable growth. Here, you'll find a place that champions growth : both professional and personal, both individual and collective.

    We invest in potential, giving you the space to stretch your capabilities and turn good ideas into reality while providing the safety net of a supportive, values-driven culture. Our approach combines meaningful work with meaningful lives, offering competitive benefits, professional development, and the flexibility to thrive both in and outside the office.

    What sets us apart isn't just what we do, but how we do it : with openness, integrity, and a shared commitment to doing the right thing. Join us in creating HR software that makes work better for everyone, while we make work better for you.

    BambooHR is committed to the full inclusion of all qualified individuals and will ensure that persons with disabilities are provided reasonable accommodations throughout the hiring process. If you would like to request accommodations, please let your recruiter know.

    BambooHR is an equal opportunity employer M / F / D / V. Because our team members are trusted to handle sensitive information, we require all candidates that receive and accept employment offers to complete a background check before being hired. For information on California Privacy Policy, click here.

    Create a job alert for this search

    Application Security Engineer • Lehi, UT, US

    Related jobs
    • Promoted
    Enterprise Architect - Security

    Enterprise Architect - Security

    BankTalent HQMidvale, UT, United States
    Full-time
    Zions Bancorporation's Enterprise Technology and Operations (ETO) team is transforming what it means to work for a financial institution. With a commitment to technology and innovation, we have been...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    Eliassen GroupSalt Lake City, UT, United States
    Full-time
    We are seeking a skilled and proactive Security Engineer to join our team.This role is critical in ensuring the integrity, confidentiality, and availability of our systems and data.The ideal candid...Show moreLast updated: 11 days ago
    • Promoted
    • New!
    Senior Manager Cyber Security - Defensive

    Senior Manager Cyber Security - Defensive

    Zions BancorporationMidvale, UT, United States
    Full-time
    Zions Bancorporation's Enterprise Technology and Operations (ETO) team is transforming what it means to work for a financial institution. With a commitment to technology and innovation, we have been...Show moreLast updated: 18 hours ago
    • Promoted
    UHealth Security Professional I

    UHealth Security Professional I

    Utah StaffingSalt Lake City, UT, US
    Full-time
    Healthcare Security Professional.Safety is a top priority for the University of Utah.The Chief Safety Officer for the University is the Director of Public Safety and serves as chief of police servi...Show moreLast updated: 6 days ago
    • Promoted
    Security Engineer - Nashville or Austin Location

    Security Engineer - Nashville or Austin Location

    OracleSalt Lake City, UT, United States
    Full-time
    Responsible for the planning, design and build of security architectures; oversees the implementation of network and computer security and ensures compliance with corporate security policies and pr...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer (Network Architecture) - Multiple levels!

    Security Engineer (Network Architecture) - Multiple levels!

    NoblisSalt Lake City, UT, United States
    Full-time +2
    We are looking for highly technical, hands-on professionals with a strong foundation in network architecture, design, and security - individuals who are ready to step up from traditional network en...Show moreLast updated: 11 days ago
    • Promoted
    • New!
    Software Architect, Network Security

    Software Architect, Network Security

    OracleSalt Lake City, UT, United States
    Full-time
    The Software Assurance team is responsible for building a new platform to perform perimeter security for OCI customers.Our mission is to build and operate a set of gateway services to perform compr...Show moreLast updated: 14 hours ago
    • Promoted
    • New!
    Senior Manager Cyber Security – Defensive

    Senior Manager Cyber Security – Defensive

    Zions BankMidvale, UT, United States
    Full-time
    Senior Manager Cyber Security – Defensive.Zions Bancorporation’s Enterprise Technology and Operations (ETO) team is transforming what it means to work for a financial institution.With a commitment ...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Security Compliance Engineer

    Security Compliance Engineer

    eBayDraper, UT, United States
    Full-time
    At eBay, we're more than a global ecommerce leader — we’re changing the way the world shops and sells.Our platform empowers millions of buyers and sellers in more than 190 markets around the world....Show moreLast updated: 14 hours ago
    Information Security Engineer, Jr - 2 Year Contract ( IAM and Platforms )

    Information Security Engineer, Jr - 2 Year Contract ( IAM and Platforms )

    Deseret Mutual Benefit AdministratorsSalt Lake City, UT, USA
    Full-time
    Quick Apply
    DMBA provides a variety of benefits including health, life, and retirement to employees of the Church of Jesus Christ of Latter-day Saints and its affiliates. DMBA began operations in 1970 and is no...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Manager Cyber Security - Defensive

    Senior Manager Cyber Security - Defensive

    Zions BankMidvale, UT, United States
    Full-time
    Zions Bancorporation's Enterprise Technology and Operations (ETO) team is transforming what it means to work for a financial institution. With a commitment to technology and innovation, we have been...Show moreLast updated: 18 hours ago
    Computer Network Defense Analyst

    Computer Network Defense Analyst

    Prime Time ConsultingBluffdale, Utah, United States, 84065
    Full-time
    Computer Network Defense Analyst.Prime Time Consulting, a GRVTY Company,.Our clients include defense contractors, industrial and service corporations, and departments and agencies of the U.Computer...Show moreLast updated: 28 days ago
    • Promoted
    • New!
    Senior Cybersecurity Engineer (Software Security)

    Senior Cybersecurity Engineer (Software Security)

    AvettaLehi, UT, United States
    Full-time
    Avetta's SaaS platform connects the world's leading organizations with qualified suppliers, contractors, and vendors.We bring unmatched visibility to companies through cloud-based technology and hu...Show moreLast updated: 12 hours ago
    • Promoted
    Application Specialist

    Application Specialist

    WavetronixSpringville, UT, United States
    Full-time
    Wavetronix is looking for an Applications Specialist who is eager to help solve customer technical problems and professionally walk them through the installation, training, and support of new and e...Show moreLast updated: 11 days ago
    • Promoted
    Application / Platform Systems Engineer

    Application / Platform Systems Engineer

    BankTalent HQSalt Lake City, UT, United States
    Full-time
    Zions Bancorporation has an opportunity for an.Application / Platform Systems Engineer.JSON, application administration, Salesforce, and ITSM experience and eager to work with various technologies to...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Manager Cyber Security – Defensive

    Senior Manager Cyber Security – Defensive

    Zions BancorporationMidvale, UT, United States
    Full-time
    Senior Manager Cyber Security – Defensive.Zions Bancorporation’s Enterprise Technology and Operations (ETO) team is transforming what it means to work for a financial institution.With a commitment ...Show moreLast updated: 2 hours ago
    • Promoted
    • New!
    Lead Adversarial Security Engineer

    Lead Adversarial Security Engineer

    TrellixSalt Lake City, UT, United States
    Full-time
    Lead Adversarial Security Engineer.Trellix, the trusted CISO ally, is redefining the future of cybersecurity and soulful work. Our comprehensive, GenAI-powered platform helps organizations confronte...Show moreLast updated: 12 hours ago
    • Promoted
    Product Security Product Owner

    Product Security Product Owner

    HumanaSalt Lake City, UT, United States
    Full-time
    Become a part of our caring community and help us put health first.The Senior Product Owner is responsible for conveying product vision, breaking down the work, building roadmap, and being the voic...Show moreLast updated: 1 day ago