Staff Application Security Engineer

Thumbtack
Ontario
Workplace: RemoteFull timeFunction: CybersecurityExperience: 8+ yearsSkills: ["Ownership","Accountability","Analytical thinking","Mentorship","Communication","Influence without authority","Risk-informed decision-making"]

Own the long-term technical direction for application security across Thumbtack. Build roadmaps, drive remediation of systemic risks, and lead cross-functional security initiatives from problem definition through delivery. Design secure-by-default architectures, standards, and reusable security tooling (libraries, patterns, services) and embed security into CI/CD pipelines, cloud infrastructure, and developer workflows. Mentor engineers, support incident response, and improve practices through post-incident learning.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Thumbtack
Thumbtack
4 months ago

Staff Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 14 hours agoStatus: Live

Job Summary

Own the long-term technical direction for application security across Thumbtack. Build roadmaps, drive remediation of systemic risks, and lead cross-functional security initiatives from problem definition through delivery. Design secure-by-default architectures, standards, and reusable security tooling (libraries, patterns, services) and embed security into CI/CD pipelines, cloud infrastructure, and developer workflows. Mentor engineers, support incident response, and improve practices through post-incident learning.
Location: Ontario
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own the long-term technical direction for application security and build prioritized roadmaps for risk remediation across the application stack.
  • •Lead large, cross-functional security initiatives from problem definition through delivery, including design reviews and architectural discussions.
  • •Design secure-by-default architectures, standards, and paved paths, and create shared security tooling, libraries, patterns, and services.
  • •Embed security into CI/CD pipelines, cloud infrastructure, and developer workflows.
  • •Mentor engineers to raise the security bar; support incident response and drive learning through post-incident analysis.

Key Requirements

  • •8+ years of software engineering and application security experience, including secure coding practices and application security frameworks.
  • •Deep expertise in secure system design and architecture, including threat modeling, secure design patterns, authentication/authorization, secrets management, and vulnerability remediation workflows.
  • •Experience leading large, cross-functional technical initiatives with sustained impact.
  • •Deep experience securing modern, cloud-native systems using AWS and/or GCP.
  • •Strong product intuition and risk-informed thinking to balance security rigor, velocity, and maintainability, with strong written and verbal communication skills.
Experience:8+ yearsCloud-nativeApplication security
Skills:OwnershipAccountabilityAnalytical thinkingMentorshipCommunicationInfluence without authorityRisk-informed decision-making
Tech Stack:AWSGCPCI/CD

Company Brief

Thumbtack
Provides an online marketplace connecting local service professionals (home improvement, events, lessons, and more) with customers seeking quotes, reviews, and booking tools to hire vetted contractors and providers.
Industry: Online Marketplaces
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2008
WebsiteLinkedIn