Sr. Application Security Engineer

| Remote | Hybrid
Sorry, this job was removed at 6:08 a.m. (CST) on Saturday, May 22, 2021
Find out who's hiring in Chicago.
See all Developer + Engineer jobs in Chicago
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

This position is open to fully-remote candidates who can work from anywhere in the United States and Canada. Candidates also have the option to work from one of our office locations in Chicago or Toronto.

Who we are: Vivid Seats is the largest independent online ticket marketplace, sending tens of millions of fans to live events. We believe in the power of experiences and are fiercely dedicated to building products that inspire human connections. Named as one of Built In Chicago's top 10 places to work in 2021, we believe that our People are our greatest competitive advantage. To support our People, we have built a company culture that empowers our employees to embrace challenges, encourages unity through collaboration, and seeks to constantly evolve by leveraging data and inspiring innovation.

The Opportunity: As a Senior Application Security Engineer, you'll be responsible for partnering with multiple software engineering teams to drive security practices and principles in a fast-paced Agile development cycle. This is a hands-on technical position best suited for a professional with developer expertise and a background collaborating with multiple groups (project, business, architecture, and operational teams) across an organization to enable business goals by melding security into solutions.

How your role contributes to the success of Vivid Seats:

  • Establish standard repeatable practices to maintain a balanced application security program based on a well-defined application security framework.
  • Introduce innovative solutions that give Vivid Seats a competitive advantage, mentor engineers, encourage team members, and champion technology security across engineering teams.
  • Work cross functionally in Agile development teams that deploy to AWS production environments on demand, multiple times a day.
  • Tackle some of the most difficult challenges securing an e-commerce marketplace by effectively embedding prudent security practices and features that maximize value, protect sensitive data, and efficiency across the organization.
  • Partner with a team of Product Owners, Quality Engineers, and Engineers to ensure security throughout the software development lifecycle deliver exceptional software, showcasing your work at the end each work cycle.
  • Implement your expertise for best practices in secure design patterns, code quality, testing, and innovation to keep our commitment of always putting our customers first and retaining their trust.
  • Ensure compliance with society, regulatory, and industry standards for application security.

How your role expectations will progress as a Senior Engineer in the first 30, 60, and 180 days:

30 days in:

  • Complete new hire orientation, gaining the resources you need to be successful.
  • Learn how ticket marketplaces operate and how you'll contribute to providing great experiences for our customers.
  • Acclimate to team and company norms, business objectives, and Vivid Seats values.
  • Develop basic understanding of applications, tech stack, and development process.
  • Understand our existing security practices, frameworks, and tools.

90 days in:

  • Enhance our approaches, methods, or technologies for dynamic and static code analysis.
  • Conduct initial application penetration tests to understand potential security vulnerabilities.
  • Partner with Quality Engineer to ensure appropriate security testing is included in the overall application testing framework.
  • Build, maintain, and leverage internal and external relationships to achieve progress and advance security objectives.
  • Apply technical learnings that align with the product roadmap and technology strategy to improve our overall security posture.
  • Support and assist in developing ongoing roadmap for security related projects.

180 days in:

  • Design and implement process improvements that positively impacts the team and our overall security posture.
  • Mentor others, playing an active role in elevating the skill sets of those you work with.
  • Provide secure application development training to engineers and provide guidance on the development of web-based training for ongoing awareness.
  • Guide the team's work so that it fits into the larger team and engineering group objectives.
  • Improve security in core systems and applications managed by the team and contribute to engineering group objectives.
  • Continuously evaluate the organization's existing application security practices, define and measure security-related activities, and demonstrating concrete improvements to the application assurance program within the organization.

What You'll Bring:

  • 5+ years of combined experience in information security, technology, and risk management with at least 2 year' experience security web applications in an e-commerce environment.
  • Hands on penetration testing experience for web applications, mobile applications, and APIs.
  • Understanding of web and mobile application security concepts (such as the OWASP top 10, CWE) with the ability to articulate concepts to technical and non-technical staff.
  • Ability to work both independently and collaboratively with peers, across teams, and with management.
  • Experience with one or more languages like Java/JavaScript, Python/Perl.
  • Familiarity with control frameworks such as ISO, SOX, NIST, CobiT, and PCI.

Our Commitment:

We are an equal opportunity employer that values the critical importance of a diverse workforce and sense of belonging. Many of our roles have flexible requirements and we encourage you to apply regardless of whether you meet every qualification. 

Vivid Seats provides competitive compensation; bonus incentives; FLEX PTO; mental health days; medical, dental, and vision insurance; 401K matching; monthly credits and discounts for attending live events; remote work and snack allowances; and a variety of additional workplace perks.

.

Read Full Job Description
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
  • People Operations
    • JavaLanguages
    • JavascriptLanguages
    • KotlinLanguages
    • PythonLanguages
    • SqlLanguages
    • SwiftLanguages
    • TypeScriptLanguages
    • jQuery UILibraries
    • ReactLibraries
    • ReduxLibraries
    • DockerFrameworks
    • JSFFrameworks
    • KafkaFrameworks
    • KubernetesFrameworks
    • Node.jsFrameworks
    • OAuthFrameworks
    • React NativeFrameworks
    • SpringFrameworks
    • TerraformFrameworks
    • Vue.jsFrameworks
    • AWS RedshiftDatabases
    • ElasticsearchDatabases
    • Microsoft SQL ServerDatabases
    • MySQLDatabases
    • SnowflakeDatabases
    • AWS (Amazon Web Services)Services
    • GitHubServices
    • New RelicServices
    • Google AnalyticsAnalytics
    • LookerAnalytics
    • FigmaDesign
    • IllustratorDesign
    • PhotoshopDesign
    • ConfluenceManagement
    • JIRAManagement
    • BrazeCRM
    • BrazeEmail
    • SlackCollaboration
    • ZoomCollaboration
    • AsanaProject Management

Location

Located in the landmark Marshall Fields building, Vivid Seats brand new HQ incorporates modern design, collaborative spaces, and the excitement of live events to create an innovative workplace. We are centrally located near public transportation hubs, shops, restaurants and entertainment venues.

An Insider's view of Vivid Seats

How does your team reward individual success?

We are encouraged to take ownership of our work and continue supporting technologies we work on, well into production and beyond. Having coworkers who care so genuinely about not only my individual success, but also the company's success, makes working for Vivid Seats extremely rewarding.

Lana M.

Quality Engineering Manager

What are Vivid Seats Perks + Benefits

Vivid Seats Benefits Overview

We make it easier for you to give it your all. While you are transforming the live event industry, we will take care of you and people who matter to you.
We've got you cover with a variety of Health, Dental and Vision packages to help fit your needs; 100% Employer Paid Life Insurance, AD&D and EAP; STD and LTD.
One of the most competitive 401 (k) programs on the market.
Continuing education opportunities and rewarding performance incentives
PTO, Maternity and Paternity policies that afford you the flexibility to take planned time off as needed.
In-office happy hours, holiday and summer events, company-sponsored sports leagues, catered lunches.
Stocked kitchen with healthy snacks!

Culture
Volunteer in local community
Committed to partner with organizations and causes that are important to our employees and our communities.
Partners with nonprofits
Corporate Social Responsibility is important to us - we have a team dedicated to leading these efforts both in a local and national scope.
Open door policy
OKR operational model
Team based strategic planning
Pair programming
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Employees trained on best practices supporting data-driven decisions - starting with recruiting and hiring.
Diversity manifesto
Mean gender pay gap below 10%
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Team workouts
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
All employees are offered equity as part of our total rewards package.
Performance bonus
Charitable contribution matching
Child Care & Parental Leave Benefits
Generous parental leave
Family medical leave
Company sponsored family events
Vacation & Time Off Benefits
Unlimited vacation policy
Generous PTO
Sabbatical
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Recreational clubs
Relocation assistance
Fitness stipend
Home-office stipend for remote employees
Onsite gym
Professional Development Benefits
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend
Continuing education available during work hours
Online course subscriptions available
Customized development tracks
Paid industry certifications

Additional Perks + Benefits

We offer credits and discounts on tickets to attend your favorite events along with great health insurance plans with healthy employer subsidies (like monthly care packages for our remote employees!) and pre-tax commuter benefits. All employees are encouraged to use no questions asks mental health days and a floating holiday. When in the office we host catered lunches and regular happy hours to recognize birthdays and celebrate successes. Our corporate office provides a fully paid in-building gym membership for morning yoga or lunchtime run. Employees are also able to work a hybrid schedule, providing the balance life requires, when we need it.

More Jobs at Vivid Seats

Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Vivid SeatsFind similar jobs like this