Skills
Ruby on Rails
React
Application security
Vulnerability remediation
Penetration testing findings analysis
Secure coding
Codebase analysis
Session traffic analysis
Infrastructure troubleshooting
Security requirements documentation
Full-stack development
Cross-functional collaboration
Penetration testing
Web application infrastructure
Summary
✨ AI‑Generated
Join a software engineering team seeking a hands-on full-stack developer with a strong application security focus. You will investigate vulnerabilities discovered through security testing, analyse code and system behaviour, implement durable fixes, and translate findings into clear, testable technical requirements. As security risks are reduced, you can contribute to new application features across a modern web stack.
Highlights
Take ownership of meaningful application security improvements, remediate vulnerabilities end to end, collaborate closely with engineering and design teams, and expand into full-stack feature development as security priorities are addressed.
Description
We are looking for a hands-on full-stack Software Engineer who will focus primarily on security remediation.
Your first priority will be owning the remediation of vulnerabilities identified through penetration testing: not just reporting findings, but digging into the codebase, session traffic, and infrastructure to fix the underlying issues and prevent them from recurring.
You will work closely with engineering and design teams to translate real-world security findings into concrete, testable requirements in our Technical Requirements Documents (TRDs), and you will personally implement or oversee the fixes.
This is an engineering role first.
As the security backlog comes under control, you will have the flexibility to contribute to application development across our Ruby on Rails and React platform, bringing a security-minded perspective to the features you build.
Key Responsibilities
Security Remediation
Vulnerability Remediation: Own end-to-end remediation of vulnerabilities surfaced by penetration tests and other security assessments, from triage through verified fixTraffic and Session Analysis: Use browser-based code inspection tools to examine session traffic between the front end and back end, identify cases where excessive or sensitive information is being exposed, and translate those findings into concrete design and engineering requirementsTRD Input: Feed vulnerability findings and remediation requirements directly into the Technical Requirements Document (TRD) process so fixes are captured as durable design requirements, not one-off patchesSession Management: Review and harden session management practices across the application stackFull-Stack Remediation: Work within a Ruby on Rails and React codebase and across containerized services (AWS, Fargate) to implement fixes at both the application and infrastructure layersAPI and Real-Time Systems: Assess and secure real-time and API-driven features, including those built on Pusher and AnyCable, and RESTful APIs generallyDocumentation: Produce clear, thorough documentation of vulnerabilities, root causes, remediation steps, and verification resultsCompliance Support: Contribute security context and vocabulary to FedRAMP-related discussions and requirements, partnering with compliance and engineering stakeholders
Application Development
Feature Development: Design, build, and ship features across the Ruby on Rails back end and React front end alongside the broader engineering teamSecure by Design: Apply what you learn from remediation work to new development, helping the team avoid reintroducing known classes of vulnerabilitiesCode Quality: Participate in code reviews, testing, and technical design discussions, with an eye toward both security and maintainability
Requirements
Engineering Experience
5+ years of hands-on software engineering experience, with broad full-stack work across multiple applications and technology layersWorking proficiency in Ruby on Rails and ReactExperience with containerized environments, AWS, and FargateSolid API experience, including RESTful API design and security considerationsHands-on experience with Pusher and AnyCable, or comparable real-time messaging technologiesKnowledge of Ruby data models and how schema and query design affect performance and scalability
Security Experience
5+ years of experience in a security engineering or closely related roleProven experience remediating vulnerabilities identified through penetration testingAWS Security certification(s) (e.g., AWS Certified Security - Specialty)General familiarity with FedRAMP: enough understanding of the vocabulary and framework to contribute meaningfully to a FedRAMP-related project
Analytical Skills
Comfortable using browser developer/code inspection tools to inspect network and session trafficAble to identify when too much information is being exposed between backend and frontend, and to explain the risk clearly to engineering and design stakeholdersAble to translate security findings into actionable design requirements that feed directly into the TRD
Coding and Technical Skills
Working proficiency in Ruby on RailsExperience with containerized environments, AWS, and FargateSolid API experience, including RESTful API design and security considerationsSolid understanding of session management principles and common pitfallsHands-on experience with Pusher and AnyCable, or comparable real-time messaging technologiesBroad, full-stack experience across multiple applications and technology layersKnowledge of Ruby data models and how schema and query design affect performance and scalability
Documentation
Strong written communication skills, with the ability to document vulnerabilities, remediations, and technical requirements clearly for both engineering and non-engineering audiences
Nice to Have
Experience with Pulumi for infrastructure as codePython experienceSQL skillsActive or eligible for security clearance