Software Security Engineer at Paylocity

| Northwest Suburbs
!Sorry, this job was removed at 3:27 p.m. (CST) on Monday, March 23, 2020

The Software Security Engineer is responsible for understanding and providing guidance to internal teams on best practices in software security and architecture for Paylocity’s Information Systems. Responsibilities will also include development and maintenance of internal application security tools, and performing threat modeling, static analysis, and dynamic analysis of our web and mobile applications.

What you'll do:

  • Develop and maintain internal application security tooling.
  • Automate security testing and vulnerability management procedures where reasonable.
  • Integrate security into the build/deployment process.
  • Promote a proactive approach to addressing the changing threat landscape by recommending and implementing architectural improvements to security infrastructure.
  • Provide expert guidance and recommendations for strategic and tactical security architecture topics through risk advisory services.
  • Perform vulnerability research, assessment and management, serve as a technical security/risk advisor on all new technologies used/developed at Paylocity such as cloud, session management, SSO, database, WAF, Opensource libraries.
  • Support offensive security professionals by suggesting remediation strategies for reported vulnerabilities.
  • Assist developers in remediating vulnerabilities by providing line-by-line guidance.
  • Provide training and education to developers on software security best practices in various cloud-based systems.
  • Utilize dynamic application vulnerability scanning using tools like White Hat Sentinel, IBM AppScan, HP WebInspect, Netsparker, AppSpider, or Cenzic Hailstorm.
  • Utilize static application vulnerability scanning using tools like HP Fortify, Checkmarx, Veracode, Coverity, etc.

What you bring:


  • Bachelors’ Degree in InfoSec, Computer Science, or a related discipline.
  • Minimum 3-5 years’ experience with full-stack web development.
  • In-depth knowledge of at least one JavaScript framework (React/Angular/etc.) or Vanilla JavaScript/JQuery.
  • Working knowledge of SQL.
  • Experience developing and working with Web APIs.
  • Experience interpreting results from Static Code Scanning tools.
  • Strong knowledge of Security Token Services, Federated Identity Providers, SAML 2.0, claims-based security and other SSO technologies.
  • Experience with creating and maintaining Threat Models at scale.
  • Experience with securing database platforms.
  • Experience in remediating security vulnerabilities beyond OWASP Top 10.
  • Experience in performing security assessments on cloud-based multi-tenant Software-as-a-Service (SaaS) applications running on the .NET platform.
  • Experience in assessing security of native and hybrid mobile applications beyond the use of automated tools.

Nice to have:

  • Experience developing in .NET is a plus.
  • Experience with NoSQL/MongoDB is a plus.
  • Experience with message-based systems (RabbitMQ/NServiceBus/etc.) is a plus.
  • Experience in at least one scripting language (Python/Ruby/Perl/PHP/etc…) is a plus.
  • Functional knowledge of container-based application infrastructure with Docker is a plus.
  • Experience working with Payroll, HR, Time & Labor Management, and Online Benefits Enrollment applications is a plus.
  • Experience with writing Burp plugins, opensource security tools, presenting at security conferences, writing technical research papers or publishing CVEs is a plus.
Read Full Job Description
Apply now

Technology we use

  • Engineering
    • C++Languages
    • JavaLanguages
    • JavascriptLanguages
    • SqlLanguages
    • AccessDatabases
    • Microsoft SQL ServerDatabases
    • OracleDatabases


Our office has modern workspaces, a cafe, and a gym. But since we're a talent-anywhere company, you may find our team members all over Chicagoland.

What are Paylocity Perks + Benefits

Paylocity Benefits Overview

Our commitment to hiring the best and brightest employees with a “talent anywhere” strategy means that no matter where you’re located around the country, you can be a part of our growing tech department

• Enjoy an attitude of trust to work remotely, manage your own schedule and be productive
• Work in small, cross-functional product-oriented teams
• Showcase development progress in two-week sprints with strong executive involvement
• Embrace the freedom to innovate, voice opinions and share new ideas

Volunteer in local community
Partners with Nonprofits
Friends outside of work
Eat lunch together
Open door policy
Team owned deliverables
Team based strategic planning
Group brainstorming sessions
Open office floor plan
Highly diverse management team
Unconscious bias training
Someone's primary function is managing the company's diversity and inclusion initiatives
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability Insurance
Dental Benefits
Vision Benefits
Health Insurance Benefits
Life Insurance
Wellness Programs
Onsite Gym
Retirement & Stock Options Benefits
401(K) Matching
Company Equity
Employee Stock Purchase Plan
Performance Bonus
Child Care & Parental Leave Benefits
Generous Parental Leave
Flexible Work Schedule
Remote Work Program
We have a talent anywhere culture, where employees can work anywhere in the US and/or work from one of three US offices located in Illinois, Florida, and Idaho
Family Medical Leave
Adoption Assistance
Company sponsored family events
Acme co. sponsors family oriented events Annually.
Vacation & Time Off Benefits
Generous PTO
Paid Volunteer Time
Paid Holidays
Paid Sick Days
Perks & Discounts
Casual Dress
Commuter Benefits
Company Outings
Game Room
Stocked Kitchen
Some Meals Provided
Happy Hours
Recreational Clubs
Fitness Subsidies
Professional Development Benefits
Job Training & Conferences
Tuition Reimbursement
Diversity Program
Lunch and learns
Acme Co. hosts lunch and learn meetings on occasion.
Cross functional training encouraged
Promote from within
Mentorship program
Our mentorship program includes 1-to-1 program, Cross-department program, Leadership mentoring.
Online course subscriptions available
More Jobs at Paylocity13 open jobs
All Jobs
Data + Analytics
Dev + Engineer
Data + Analytics
Northwest Suburbs
Northwest Suburbs
Northwest Suburbs
Data + Analytics
Northwest Suburbs
Northwest Suburbs
Northwest Suburbs
Data + Analytics
Northwest Suburbs
Northwest Suburbs
Northwest Suburbs
Northwest Suburbs