Talent.com
Senior Security Engineer - Application & Product Security
Senior Security Engineer - Application & Product SecurityCaptivateIQ • Nashville, TN, US
Senior Security Engineer - Application & Product Security

Senior Security Engineer - Application & Product Security

CaptivateIQ • Nashville, TN, US
1 day ago
Job type
  • Full-time
Job description

Job Description

Job Description

CaptivateIQ is transforming the way companies plan, manage, and optimize sales performance. We started by revolutionizing incentive compensation management, and now we're expanding our platform to solve broader sales planning challenges. Recognized by industry analysts like Forrester and G2 and backed by top-tier investors, including Sequoia, ICONIQ and Accel, we empower high-growth companies like Netflix, Figma and Stripe with the flexibility and insights needed to drive revenue performance.

Join a talented, fast-growing team committed to solving some of the most complex and impactful problems in sales performance management.

About the Role

Security is a core value at CaptivateIQ. As we scale and expand our suite of services, embedding security into every phase of product development is critical to building trust in everything we deliver.

As a Senior Security Engineer focused on Application & Product Security , you will own our AppSec strategy - driving threat modeling, secure architecture design, and offensive security testing . You will lead manual and automated penetration testing, manage AppSec tooling (SAST, DAST, SCA), and build developer enablement programs. You’ll also be responsible for vulnerability management, incident response for application-layer events, and ensuring compliance alignment for SOC 2, ISO 27001, and privacy requirements.

This role blends offensive and defensive expertise with strategic influence, giving you the autonomy to shape a scalable, modern AppSec program.

Job Location

Remote

Raleigh, NC

Nashville, TN

Toronto, Canada

Responsibilities

  • Threat Modeling & Architecture Reviews Mature and scale a modern threat modeling program across products and services. Enable secure by design architectures in collaboration with Engineering teams.
  • Offensive Security Testing Conduct penetration tests (white-box and black-box) for web applications and APIs. Perform dynamic (DAST), static (SAST), and software composition (SCA) analysis. Simulate adversary attack scenarios to validate controls and identify gaps.
  • Secure SDLC Integration Embed security into every stage of development; implement automated security tooling in CI / CD pipelines.
  • Vulnerability Management Triage and prioritize application-layer vulnerabilities and guide engineering teams through remediation.
  • Developer Enablemen t Deliver secure development and coding training; create resources to reduce recurring vulnerabilities.
  • Bug Bounty Management Oversee Bug Bounty program, validate findings, and ensure timely resolution.
  • Incident Response Leadership Lead investigations for application-layer security incidents and conduct post-incident analysis.
  • Compliance Enablement Support audits, technical evidence collection, and control design for SOC 2, ISO 27001, and privacy-by-design requirements.
  • Customer Trust Contribute to customer security assessments, penetration test reports, and security documentation.

Requirements

  • 7+ years of experience in a security engineer or related role, including 4+ years specializing in web application, API, and product security.
  • Deep expertise securing multi-tenant SaaS platforms and features.
  • Strong communication and ability to influence software engineers and product managers.
  • Advanced experience conducting penetration tests, code reviews, and vulnerability assessments.
  • Expert knowledge of OWASP Top 10, web application and API security, and common vulnerability classes with practical remediation strategies.
  • Hands-on experience with AppSec tooling (SAST, DAST, SCA) integrated into CI / CD pipelines.
  • Strong programming and scripting skills (Python preferred) and ability to influence secure coding practices.
  • Proven ability to lead incident response for application-layer security events.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001) and secure SDLC practices.
  • Knowledge of privacy-by-design principles and data security in SaaS environments.
  • Awareness of emerging AI / ML security risks and related countermeasures.
  • Nice to have

  • Certifications such as OSCP, GCIH, GWAPT, or CISSP.
  • Familiarity with security frameworks such as NIST CSF, MITRE ATT&CK, OWASP ASVS, or ISO 27001.
  • Experience with commercial security tools such as EDR, SIEM, CSPM, CNAPP, vulnerability scanners, bug bounty platforms, WAFs, or compliance automation platforms.
  • Prior experience driving security engineering for a SaaS-based company.
  • Experience leveraging automation or AI / ML tools to improve secure development, detection, incident response, or code analysis workflows.
  • Benefits

  • (US-ONLY) 100% of medical, dental, and vision covered including 75% for dependents
  • Flexible vacation days and quarterly mental health days so you can recharge
  • Enjoy a one-time expense on your 1-year work anniversary (to use for travel, home furnishings, fancy meal)
  • (US-ONLY) 401k plan to participate in and save towards the future
  • Newest Apple products to help you do your best work
  • Employee Resource Groups (ERGs) to support and celebrate the shared identities and life experiences of communities within CaptivateIQ. ERGs directly support our company-wide DEI goals as a space for developing and retaining diverse talent
  • Notice to Prospective Candidates

  • Only emails from @captivateiq.com should be trusted.
  • We are aware of active recruitment scams using the CaptivateIQ name, in which individuals pose as our recruiters and post fake remote job openings and make fake job offers on the Internet. Please note, we will never do the following :
  • Attempt to correspond with a candidate using a free web-based account, such as an email address that ends in @gmail.com, @yahoo.com, @hotmail.com, etc.
  • Make an offer of employment without conducting multiple rounds of interviews face-to-face using secure video-conferencing technology.
  • Ask candidates to cash checks to buy equipment on behalf of CaptivateIQ.
  • Ask candidates to make a payment in order to be considered for a position.
  • Make early requests for candidates' personal information such as date of birth, passport details, credit card numbers, bank details and social security number, etc.
  • Please note that we’ll only ask for more sensitive personal information in connection with background checks after an offer is made.
  • Participate in an on-call rotation to provide after-hours support, ensuring timely resolution of critical issues and maintaining system uptime.
  • The base range represents the minimum and maximum for this position across North America. For candidates in Raleigh , the range is $170,980–$197,760; for Toronto, and Nashville locations, the range is $154,500–$177,160. The compensation offered for this position will depend on numerous factors, including individual proficiency, anticipated performance, and the location of the selected candidate. Our OTE is just one component of CaptivateIQ's competitive total rewards package.

    CaptivateIQ participates in E-Verify, web-based system that allows enrolled employers to confirm the eligibility of their employees to work in the United States

    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    Create a job alert for this search

    Application Security Engineer • Nashville, TN, US

    Related jobs
    Electronic Warfare Specialist

    Electronic Warfare Specialist

    United States Army • Nashville, TN, United States
    Full-time
    ELIGIBLE FOR UP TO A $16K SIGNING BONUS.Talk to your recruiter for details.As an Electromagnetic Warfare Specialist, you’ll plan and execute electronic warfare operations.You’ll be trained to detec...Show more
    Last updated: 30+ days ago • Promoted
    Radiology Systems Manager - PACS Experience

    Radiology Systems Manager - PACS Experience

    Williamson Health • Spring Hill, TN, US
    Full-time
    ABOUT WILLIAMSON HEALTH | Williamson Health is a regional healthcare system based in Williamson County, Tennessee, with more than 2,300 employees across more than 30 locations and more than 860 phy...Show more
    Last updated: 30+ days ago • Promoted
    Order Picker

    Order Picker

    Walmart • Readyville, TN
    Full-time
    As an Order Picker at Walmart, you will be responsible for accurately and efficiently selecting merchandise from storage locations to fulfill customer orders or replenish inventory for Walmart stor...Show more
    Last updated: 11 days ago • Promoted
    Precision Mechanical Assembly Specialist

    Precision Mechanical Assembly Specialist

    AMS Seals Inc • Fairview, TN, US
    Full-time
    Precision Mechanical Assembly Specialist.You arrive on the floor, review the day’s build plan, and prep your workcell.You ready the equipment, verify settings, and complete a quick safety che...Show more
    Last updated: 1 day ago • Promoted
    Information Security Engineer

    Information Security Engineer

    Ramsey Solutions • Nashville, TN, US
    Full-time
    Please note that applicants must be authorized to work in the U.We are unable to sponsor or take over sponsorship of an employment Visa at this time. Franklin, TN—on-site, relocation assistance avai...Show more
    Last updated: 18 days ago
    Security Specialist

    Security Specialist

    Security Industry Specialists, Inc. • Nashville, Tennessee, United States
    Full-time
    Quick Apply
    The Security Specialists, under the direct supervision of the Shift Supervisor, ensures SIS standards and policies are met in overall field services, operations and functions in assigned area such ...Show more
    Last updated: 30+ days ago
    Senior Product Analyst

    Senior Product Analyst

    MCKESSON • TN, United States
    Full-time
    It’s More Than a Career, It’s a Mission.Our people are the foundation of our success.By joining our growing team at Sarah Cannon Research Institute (SCRI), a subsidiary of McKesson, you will have t...Show more
    Last updated: 30+ days ago • Promoted
    Director of Product Development

    Director of Product Development

    Enexor • Franklin, TN, US
    Full-time
    Launch Modular Systems That Scale.Location : Franklin, TN (On-Site).Seniority : Director / Hardware Product Leadership.Enexor is a venture-backed climate tech company outside Nashville, building modu...Show more
    Last updated: 30+ days ago • Promoted
    Greeter

    Greeter

    Walmart • Beechgrove, TN
    Full-time
    As a Greeter at Walmart, you will be the first point of contact for customers as they enter the store.Your warm and friendly demeanor will create a welcoming atmosphere and set the tone for a posit...Show more
    Last updated: 30+ days ago • Promoted
    Nuclear Engineer

    Nuclear Engineer

    Navy • Columbia, TN, US
    Full-time
    ABOUT Nuclear technicians, power plant operators, and subsystems specialists are responsible for keeping vital Naval submarines and aircraft carriers running. These highly trained, hands-on professi...Show more
    Last updated: 30+ days ago • Promoted
    Sr. Network Security Engineer

    Sr. Network Security Engineer

    Two95 International Inc. • Nashville, TN, US
    Full-time
    Quick Apply
    Minimum of 8 years’ experience (preferred); (At least 5 years of experience with cybersecurity or information assurance). .BS degree in Computer Science or related field (required); MS degree (prefe...Show more
    Last updated: 30+ days ago
    Border Patrol Agent

    Border Patrol Agent

    U.S. Customs and Border Protection • Bell Buckle, TN, US
    Full-time
    Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of highly trained professionals whose camaraderie, p...Show more
    Last updated: 2 days ago • Promoted
    AI Security Architect (REMOTE)

    AI Security Architect (REMOTE)

    EnableComp • Franklin, TN, United States
    Remote
    Full-time
    EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise and its unified. Powered by proprietary algorith...Show more
    Last updated: 30+ days ago • Promoted
    Director, Application Engineering

    Director, Application Engineering

    MCKESSON • TN, United States
    Full-time
    It’s More Than a Career, It’s a Mission.Our people are the foundation of our success.By joining our growing team at Sarah Cannon Research Institute (SCRI), a subsidiary of McKesson, you will have t...Show more
    Last updated: 30+ days ago • Promoted
    Manufacturing Engineer - Manufacturing - Base Salary to 105k / year - Ashland City, TN

    Manufacturing Engineer - Manufacturing - Base Salary to 105k / year - Ashland City, TN

    AllSearch Professional Staffing • Ashland City, TN, US
    Full-time
    Manufacturing Engineer - Manufacturing - Base Salary to 105k / year - Ashland City, TN.Our client is a global manufacturer, with 12,000 employees and operations across seven countries, produces resid...Show more
    Last updated: 1 day ago • Promoted
    Senior Associate, Industrial Security

    Senior Associate, Industrial Security

    Clearance Jobs • Nashville, TN, US
    Full-time
    Senior Associate, Industrial Security.L3Harris, ForceX division is an industry leader specializing in Intelligence Surveillance and Reconnaissance (ISR) software development and geospatial applicat...Show more
    Last updated: 30+ days ago • Promoted
    Network Security Engineer - Manufacturing

    Network Security Engineer - Manufacturing

    Akaasa Technologies • TN, United States
    Full-time
    Quick Apply
    They have to be out of a manufacturing, utilities, or critical infrastructure, be open to EXTENSIVE travel and have EXCELLENT communication skills. This is extensive travel position to client sites ...Show more
    Last updated: 4 days ago
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    Relativity • Nashville, TN, United States
    Full-time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...Show more
    Last updated: 30+ days ago • Promoted