Security Engineer (App Sec and Cloud Infra)

Thumbtack
Ontario
Workplace: RemoteFull timeUSD 154,700 - 200,200 annuallyFunction: CybersecurityExperience: 4+ yearsSkills: ["Ownership","Independent execution","Written communication","Verbal communication","Growth mindset"]

Own application security within defined projects, delivering scoped security initiatives that help teams ship securely as Thumbtack scales. Identify and remediate app security risks in partnership with engineering, applying secure-by-default patterns and approved architectures. Integrate security controls into CI/CD pipelines, IAM, networking, and runtime environments. Participate in design reviews, threat modeling, and incident response, writing code, reviews, and documentation to reduce recurring vulnerability classes.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Thumbtack
Thumbtack
6 months ago

Security Engineer (App Sec and Cloud Infra)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 14 hours agoStatus: Live

Job Summary

Own application security within defined projects, delivering scoped security initiatives that help teams ship securely as Thumbtack scales. Identify and remediate app security risks in partnership with engineering, applying secure-by-default patterns and approved architectures. Integrate security controls into CI/CD pipelines, IAM, networking, and runtime environments. Participate in design reviews, threat modeling, and incident response, writing code, reviews, and documentation to reduce recurring vulnerability classes.
Location: Ontario
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own and deliver application security work within defined projects or domains.
  • •Contribute to cross-functional security initiatives by executing clearly scoped pieces of larger efforts.
  • •Identify, prioritize, and help remediate application security risks with engineering teams.
  • •Support cloud infrastructure security by integrating security controls into CI/CD pipelines, IAM, networking, and runtime environments.
  • •Participate in application security design reviews and threat modeling; write code, reviews, and documentation for vulnerabilities and support incident response and post-incident remediation.

Pay and Benefits

Salary: USD 154,700 - 200,200 annually

Key Requirements

  • •4+ years of experience in software engineering, application security, or cloud infrastructure security.
  • •Practical experience with application security techniques including threat modeling, secure design patterns, authentication and authorization, secrets management, and vulnerability remediation.
  • •Strong understanding of secure coding practices and common application security risks (e.g., OWASP Top 10).
  • •Experience securing cloud-native systems in AWS and/or GCP.
  • •Ability to assess security risks, break down complex problems, reason about tradeoffs, and deliver practical risk-informed recommendations.
Experience:4+ yearsCloud-nativeApplication security
Skills:OwnershipIndependent executionWritten communicationVerbal communicationGrowth mindset
Tech Stack:AWSGCPCI/CDIAMNetworkingRuntime environments

Company Brief

Thumbtack
Provides an online marketplace connecting local service professionals (home improvement, events, lessons, and more) with customers seeking quotes, reviews, and booking tools to hire vetted contractors and providers.
Industry: Online Marketplaces
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2008
WebsiteLinkedIn