Staff Security Engineer, Kandji

AppSec

$190-230k

+ Equity

AWS
GCP
JavaScript
Python
Go
Azure
Senior and Expert level
Miami

More information about location

4+ days a week in office

Kandji

Apple device management platform

Open for applications

Kandji

Apple device management platform

201-500 employees

B2BEnterpriseComplianceSaaSCyber Security

Open for applications

$190-230k

+ Equity

AWS
GCP
JavaScript
Python
Go
Azure
Senior and Expert level
Miami

More information about location

4+ days a week in office

201-500 employees

B2BEnterpriseComplianceSaaSCyber Security

Company mission

To harmonize technology and security through innovative software that powers secure and productive global work.

Role

Who you are

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field, or equivalent experience
  • 8+ years of experience in application security, preferably within a SaaS environment
  • Strong proficiency in threat modeling, secure coding practices, vulnerability management, and incident response
  • Hands-on experience with security tools such as static/dynamic analysis tools (SAST, DAST), penetration testing tools, and CI/CD pipeline integration
  • Familiarity with modern programming languages (e.g., Python, JavaScript, Go) and cloud platforms (e.g., AWS, GCP, Azure)
  • Industry certifications such as CISSP, OSCP, or CEH are a plus
  • Technical Leadership: Demonstrated ability to lead and guide teams in the development and execution of security initiatives
  • Threat Analysis: Strong understanding of threat modeling techniques, application security risks (OWASP Top Ten), and secure coding practices
  • Risk Management: Expertise in managing security vulnerabilities and threats through identification, prioritization, and mitigation strategies
  • Communication: Excellent communication skills to effectively collaborate with cross-functional teams, present complex security concepts, and advocate for secure design practices
  • Innovation & Problem Solving: Creative thinker with the ability to develop novel security solutions in response to emerging threats and vulnerabilities
  • Continuous Improvement: Strong commitment to staying up-to-date with evolving security standards and best practices, and a passion for continuous learning and improvement

What the job involves

  • The Staff Security Engineer, AppSec will play a critical role in safeguarding Kandji’s products and infrastructure by designing security programs, conducting thorough threat modeling, managing vulnerabilities, and embedding secure development practices
  • This role will work closely with product managers, engineering teams, and cross-functional stakeholders to ensure security is a foundational component of all our initiatives
  • Threat Modeling: Lead the development of comprehensive threat models for new and existing products to identify, assess, and mitigate security risks
  • Vulnerability Management: Establish and manage a vulnerability management lifecycle for our applications, ensuring timely detection, reporting, and remediation of security vulnerabilities
  • Security Programs: Design and implement application security programs focused on building security into the software development lifecycle (SDLC) and establishing secure coding practices
  • Collaboration with Engineering: Partner with product and engineering teams to integrate security requirements into architectural designs and development processes
  • Security Audits & Assessments: Conduct regular security assessments of applications and infrastructure, focusing on identifying areas of weakness and recommending actionable improvements
  • Security Incident Response: Support the incident response team in application-related security incidents by providing expertise on containment, eradication, and post-incident analysis
  • Security Awareness: Mentor and coach engineering teams on security best practices and create security awareness initiatives tailored to the development environment
  • Automation & Tooling: Drive the adoption of security automation, including code scanning, security testing, and CI/CD pipeline integration to streamline security processes

Our take

Device and application management is essential for the maintenance of an IT stack, with particular emphasis on frequent updating and compliance. This can be a laborious and repetitive task, so management software exists to automate these processes. However, existing solutions are generally aimed towards IT departments running on Windows.

Kandji provides a mobile device management platform that facilitates the remote maintenance of Apple-based IT stacks. Users can manage IT devices, applications, networking and compliance within a zero-touch automation system. The need for this service in companies using Apple hardware is clear: it has been adopted by major enterprises such as Belkin, Crunchbase and Notion.

Launched in 2019, the company has completed multiple rounds of funding and is continuing to grow at a rapid pace. As the Apple device management market is also expanding at speed, Kandji is well poised to continue its run of success.

Freddie headshot

Freddie

Company Specialist at Welcome to the Jungle

Insights

Top investors

Some candidates hear
back within 2 weeks

-5% employee growth in 12 months

Company

Funding (last 2 of 6 rounds)

Jul 2024

$100m

SERIES D

Nov 2021

$100m

SERIES C

Total funding: $288.4m

Company benefits

  • Health Coverage - 100% individual and dependent medical + dental + vision coverage
  • Flexible Spending Account
  • Equity for full-time employees
  • New MacBook Pro and software setup
  • Exciting opportunities for career growth
  • An outstanding, inclusive culture
  • 4% 401k company match
  • Monthly Uber Eats meal credit
  • $1,000 Home Office Equipment Stipend
  • $50 monthly Internet reimbursement
  • Equipment discounts
  • Week long company shutdown, first week of August
  • 10 Health and Wellness Days
  • 12 weeks of Paid Parental Leave
  • 14 Holidays

Company HQ

Downtown San Diego, San Diego, CA

Leadership

They started their career in Solutions at Apple before working as President of AMP Consulting and spending 9 years as CEO of Interlaced, which they founded. They left to found Kandji in 2018 as CEO.

Salary benchmarks

We don't have enough data yet to provide salary benchmarks for this role.

Submit your salary to help other candidates with crowdsourced salary estimates.

Share this job

View 28 more jobs at Kandji