Talent.com
Senior Security Engineer - Application & Product Security in Nashville

Senior Security Engineer - Application & Product Security in Nashville

Energy Jobline ZRNashville, TN, United States
1 day ago
Job type
  • Full-time
Job description

Energy Jobline is the largest and fastest growing global Energy Job Board and Energy Hub. We have an audience reach of over 7 million energy professionals, 400,000+ monthly advertised global energy and engineering jobs, and work with the leading energy companies worldwide.

We focus on the Oil & Gas, Renewables, Engineering, Power, and Nuclear markets as well as emerging technologies in EV, Battery, and Fusion. We are committed to ensuring that we offer the most exciting career opportunities from around the world for our jobseekers.

Job DescriptionJob DescriptionCaptivateIQ is transforming the way companies plan, manage, and optimize sales performance. We started by revolutionizing incentive compensation management, and now we're expanding our platform to solve broader sales planning challenges. Recognized by industry analysts like Forrester and G2 and backed by top-tier investors, including Sequoia, ICONIQ and Accel, we empower high-growth companies like Netflix, Figma and Stripe with the flexibility and insights needed to drive revenue performance.

Join a talented, fast-growing team committed to solving some of the most complex and impactful problems in sales performance management.

About the Role Security is a core value at CaptivateIQ. As we scale and expand our suite of services, embedding security into every phase of product development is critical to building trust in everything we deliver.

As a Senior Security Engineer focused on Application & Product Security , you will own our AppSec strategy - driving threat modeling, secure architecture design, and offensive security testing . You will lead manual and automated penetration testing, manage AppSec tooling (SAST, DAST, SCA), and build developer enablement programs. You’ll also be responsible for vulnerability management, incident response for application-layer events, and ensuring compliance alignment for SOC 2, ISO 27001, and privacy requirements.

This role blends offensive and defensive expertise with strategic influence, giving you the autonomy to shape a scalable, modern AppSec program.

Job Location

Remote Raleigh, NC Nashville, TN Toronto, Canada

Responsibilities

  • Threat Modeling & Architecture Reviews Mature and scale a modern threat modeling program across products and services. Enable secure by design architectures in collaboration with Engineering teams.
  • Offensive Security Testing Conduct penetration tests (white-box and black-box) for web applications and APIs. Perform dynamic (DAST), static (SAST), and software composition (SCA) analysis. Simulate adversary attack scenarios to validate controls and identify gaps.
  • Secure SDLC Integration Embed security into every stage of development; implement automated security tooling in CI / CD pipelines.
  • Vulnerability Management Triage and prioritize application-layer vulnerabilities and guide engineering teams through remediation.
  • Developer Enablemen t Deliver secure development and coding training; create resources to reduce recurring vulnerabilities.
  • Bug Bounty Management Oversee Bug Bounty program, validate findings, and ensure timely resolution.
  • Incident Response Leadership Lead investigations for application-layer security incidents and conduct post-incident analysis.
  • Compliance Enablement Support audits, technical evidence collection, and control design for SOC 2, ISO 27001, and privacy-by-design requirements.
  • Customer Trust Contribute to customer security assessments, penetration test reports, and security documentation.

Requirements

  • 7+ years of experience in a security engineer or related role, including 4+ years specializing in web application, API, and product security.
  • Deep expertise securing multi-tenant SaaS platforms and features.
  • Strong communication and ability to influence software engineers and product managers.
  • Advanced experience conducting penetration tests, code reviews, and vulnerability assessments.
  • Expert knowledge of OWASP Top 10, web application and API security, and common vulnerability classes with practical remediation strategies.
  • Hands-on experience with AppSec tooling (SAST, DAST, SCA) integrated into CI / CD pipelines.
  • Strong programming and scripting skills (Python ) and ability to influence secure coding practices.
  • Proven ability to lead incident response for application-layer security events.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001) and secure SDLC practices.
  • Knowledge of privacy-by-design principles and data security in SaaS environments.
  • Awareness of emerging AI / ML security risks and related countermeasures.
  • Nice to have

  • Certifications such as OSCP, GCIH, GWAPT, or CISSP.
  • Familiarity with security frameworks such as NIST CSF, MITRE ATT&CK, OWASP ASVS, or ISO 27001.
  • Experience with commercial security tools such as EDR, SIEM, CSPM, CNAPP, vulnerability scanners, bug bounty platforms, WAFs, or compliance automation platforms.
  • Prior experience driving security engineering for a SaaS-based company.
  • Experience leveraging automation or AI / ML tools to improve secure development, detection, incident response, or code analysis workflows.
  • Benefits

  • (US-ONLY) 100% of medical, dental, and vision covered including 75% for dependents
  • Flexible vacation days and quarterly mental health days so you can recharge
  • Enjoy a one-time expense on your 1-year work anniversary (to use for travel, home furnishings, fancy meal)
  • (US-ONLY) 401k plan to participate in and save towards the future
  • Newest Apple products to help you do your best work
  • Employee Resource Groups (ERGs) to support and celebrate the shared identities and life experiences of communities within CaptivateIQ. ERGs directly support our company-wide DEI goals as a space for developing and retaining diverse talent
  • Notice to Prospective Candidates

  • Only emails from @captivateiq.com should be trusted.
  • We are aware of active recruitment scams using the CaptivateIQ name, in which individuals pose as our recruiters and post fake remote job openings and make fake job offers on the Internet. Please note, we will never do the following :
  • Attempt to correspond with a candidate using a free web-based account, such as an email address that ends in @gmail.com, @yahoo.com, @hotmail.com, etc.
  • Make an offer of employment without conducting multiple rounds of interviews face-to-face using secure video-conferencing technology.
  • Ask candidates to cash checks to buy equipment on behalf of CaptivateIQ.
  • Ask candidates to make a payment in order to be considered for a position.
  • Make early requests for candidates' personal information such as date of birth, passport details, credit card numbers, bank details and social security number, etc.
  • Please note that we’ll only ask for more sensitive personal information in connection with background checks after an offer is made.
  • Participate in an on-call rotation to provide after-hours support, ensuring timely resolution of critical issues and maintaining system uptime.
  • The base range represents the minimum and maximum for this position across North America. For candidates in Raleigh , the range is $170,980–$197,760; for Toronto, and Nashville locations, the range is $154,500–$177,160. The compensation offered for this position will depend on numerous factors, including individual proficiency, anticipated performance, and the location of the selected candidate. Our OTE is just one component of CaptivateIQ's competitive total rewards package.CaptivateIQ participates in E-Verify, web-based system that allows enrolled employers to confirm the eligibility of their employees to work in the United States

    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    If you are interested in applying for this job please press the Apply Button and follow the application process. Energy Jobline wishes you the very best of luck in your next career move.

    Create a job alert for this search

    Security Engineer Security • Nashville, TN, United States

    Related jobs
    • Promoted
    Security Engineer II

    Security Engineer II

    TrustmarkNashville, TN, United States
    Full-time
    Trustmark's mission is to improve wellbeing - for everyone.It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust.Tr...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer

    Security Engineer

    Info Way SolutionsNashville, TN, United States
    Full-time
    As a Secure SDLC Policy developer will play a critical role in establishing a comprehensive Secure Software Development Life Cycle (Secure SDLC) policy that can be implemented and leveraged across ...Show moreLast updated: 1 day ago
    • Promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    RelativityNashville, TN, United States
    Full-time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer

    Security Engineer

    Eliassen GroupNashville, TN, United States
    Full-time
    We are seeking a skilled and proactive Security Engineer to join our team.This role is critical in ensuring the integrity, confidentiality, and availability of our systems and data.The ideal candid...Show moreLast updated: 1 day ago
    • Promoted
    Security Solutions Engineer II

    Security Solutions Engineer II

    ProofpointNashville, TN, United States
    Full-time
    We are the leader in human-centric cybersecurity.Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer - Secure Software Development

    Security Engineer - Secure Software Development

    SedgwickNashville, TN, United States
    Full-time
    By joining Sedgwick, you'll be part of something truly meaningful.It's what our 33,000 colleagues do every day for people around the world who are facing the unexpected. We invite you to grow your c...Show moreLast updated: 1 day ago
    • Promoted
    Senior Cyber Security Engineer, Vulnerability Management (Remote)

    Senior Cyber Security Engineer, Vulnerability Management (Remote)

    Community Health SystemsFranklin, TN, United States
    Remote
    Full-time
    As a member of the Cyber Security team, the Cyber Security Senior Engineer for Vulnerability Management will be responsible for developing, implementing, and operating vulnerability management solu...Show moreLast updated: 1 day ago
    • Promoted
    Sr. Security Engineer

    Sr. Security Engineer

    NutanixNashville, TN, United States
    Full-time
    Hungry, Humble, Honest, with Heart.Are you a proactive and strategic Security Engineer with a passion for identity and access management, data loss prevention, and a strong ability to lead collabor...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer

    Security Engineer

    Jobs via DiceLa Vergne, TN, United States
    Full-time
    Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.We are looking for a skilled Security Engineer to join our team. In this role, you will play a pivotal ...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer •Remote •

    Security Engineer •Remote •

    Broadcast MusicNashville, TN, United States
    Remote
    Full-time
    Supports solution design, implementation, configuration, security infrastructure, and application components.Focuses on core security technologies to ensure they are in compliance with security ind...Show moreLast updated: 1 day ago
    • Promoted
    Offensive Security Engineer, Assessments (Web3)

    Offensive Security Engineer, Assessments (Web3)

    CoinbaseNashville, TN, United States
    Full-time
    Ready to be pushed beyond what you think you’re capable of?.At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, ...Show moreLast updated: 1 day ago
    • Promoted
    Senior Cyber Security Engineer, Security Validation (Remote)

    Senior Cyber Security Engineer, Security Validation (Remote)

    Community Health SystemsFranklin, TN, United States
    Remote
    Full-time
    As a Senior Cybersecurity Engineer in the Security Validation team, you will be a key member of our Red Team operations, leading efforts to emulate real-world threat scenarios and validate the effe...Show moreLast updated: 1 day ago
    • Promoted
    Senior Cyber Security Engineer, Mobile Device Protection (Remote)

    Senior Cyber Security Engineer, Mobile Device Protection (Remote)

    Community Health SystemsFranklin, TN, United States
    Remote
    Full-time
    As a Mobile Device Security Senior Engineer, this role reports to the Manager of Endpoint Security.This role develops, engineers, and maintains the Mobile Device product within the Endpoint Securit...Show moreLast updated: 1 day ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    OracleNashville, TN, United States
    Full-time
    Security Architecture is comprised of security experts who are focused and specialized in securing all aspects of Oracle Cloud. As security experts, we are sought out by our partner organizations to...Show moreLast updated: 1 day ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Tennessee StaffingNashville, TN, United States
    Full-time
    Security Architecture Engineer.Security Architecture is comprised of security experts who are focused and specialized in securing all aspects of Oracle Cloud. As security experts, we are sought out ...Show moreLast updated: 1 day ago
    • Promoted
    Senior Security Engineer - Data Loss Prevention Operations

    Senior Security Engineer - Data Loss Prevention Operations

    OracleNashville, TN, United States
    Full-time
    Our rapidly growing team specializes in threat hunting, analyzing indicators of compromise (IOCs), investigating security incidents, managing incident responses, and conducting digital forensics ac...Show moreLast updated: 1 day ago
    • Promoted
    Sr. Security Research Engineer

    Sr. Security Research Engineer

    ProofpointNashville, TN, United States
    Full-time
    We are the leader in human-centric cybersecurity.Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We’re driven by a mission to stay ahead...Show moreLast updated: 1 day ago
    • Promoted
    Hardware Security Consulting Engineer

    Hardware Security Consulting Engineer

    OracleNashville, TN, United States
    Full-time
    As consulting hardware security engineer, you will be responsible for defining security requirements for hardware used within OCI, conducting security / architectural reviews and assessments, offensi...Show moreLast updated: 1 day ago