Senior Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $160k - $220k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Lime

Lime

501 - 1000 employees

Founded 2017

🚗 Transport

🛍️ eCommerce

☁️ SaaS

💰 $418M Convertible Note on 2021-11

Transport • eCommerce • SaaS

Lime is a transportation company that provides shared electric scooters and bikes in urban areas, making it easy for users to travel short distances. With a focus on safety, sustainability, and community, Lime aims to offer an eco-friendly alternative to traditional transportation methods. Users can easily locate and rent vehicles through the Lime app, promoting responsible riding and parking practices to enhance the urban mobility experience.

📋 Description

• Application Security & Secure Development: Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services. Provide actionable and risk-calibrated guidance that helps Lime ship securely without slowing down. • Security Tooling & Automation: Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle. Contribute to and extend our security pipeline and CI/CD security gates (SAST, DAST, SCA, secrets management). • Security Architecture & Design Reviews: Contribute to security architecture reviews for new product platforms and features. Evaluate authentication and authorization designs, API security posture, and data handling practices to ensure risks are identified and addressed early. • Bug Bounty & External Programs: Support the operations of our BugCrowd bug bounty program, including triage, researcher communication, remediation coordination, and internal validation of reported findings. • Incident Response: Serve as a product security point of contact for security incidents affecting Lime's applications and services. Contribute to investigation, root-cause analysis, corrective action, and post-incident improvement. • Cross-functional Partnership & Mentorship: Work closely with Software, Platform, Mobile, and Infrastructure engineering teams to embed security into development workflows. Share knowledge, drive security-by-default practices, and mentor engineers and peers on product security fundamentals. • Stay Ahead of the Threat Landscape: Continuously evaluate emerging threats, vulnerabilities, and regulatory requirements (including EU CRA) relevant to Lime's product and infrastructure stack. Bring proactive recommendations to the team. • Participate in the team's on-call rotation, responding to incidents, troubleshooting issues, and contributing to root cause analysis and service reliability improvements. • Respond to and troubleshoot production issues, outages, and critical alerts during assigned on-call shifts. • Escalate incidents as needed and collaborate with team members to restore service. • Document issues and contribute to improvements that reduce recurring incidents. • Be available to provide occasional after-hours, weekend, and holiday support while on call.

🎯 Requirements

• Experience: 5+ years of experience in a dedicated product security, application security, or security engineering role, with a strong track record of hands-on technical contribution across the software development lifecycle. • Technical Depth: Demonstrated expertise across core product and application security domains, including: • Experience with detection engineering, security monitoring, or building detection-as-code (DaC) pipelines for product or application security threats (SIEM, log analysis, alert tuning). • Familiarity with IoT, connected hardware, or vehicle/firmware security in a product security context. • Experience operating or contributing to a vulnerability disclosure or bug bounty program. • Exposure to regulatory frameworks relevant to connected products, such as EU CRA, UNECE WP.29, or OWASP MASVS. • Mobile security (iOS, Android) and API security • Secure development practices and SDLC security integration (SAST, DAST, SCA, secrets management) • Vulnerability management tooling and processes • Cloud security fundamentals (AWS, GCP) and container/infrastructure security • Authentication and authorization patterns (OAuth, OIDC, RBAC) • Problem-Solver: Strong analytical skills with the ability to triage ambiguous security signals, identify meaningful risk, and propose pragmatic mitigations that teams can act on — without over-engineering or adding unnecessary friction. • Communication: Clear written and verbal communicator who can translate complex technical security risks into actionable guidance for both engineering peers and non-technical stakeholders. • Team Player: Comfortable operating in a lean, remote-first, high-trust environment. Able to independently drive work forward while collaborating across engineering, product, and security teams. • Education & Certifications: Bachelor's degree in Computer Science, Cybersecurity, or a related field preferred but not required. Relevant certifications such as OSCP, CSSLP, GWEB, or equivalent are a plus. • Ability to participate in a shared on-call rotation supporting production systems, including occasional after-hours, weekend, and holiday coverage, with responsibility for responding to critical alerts, coordinating escalations to restore service, and documenting issues to help prevent recurrence.

🏖️ Benefits

• Comprehensive Health & Wellness: A choice of medical, dental, and vision plans. We also provide company-paid life and disability insurance and company-funded mental health benefits. • Financial & Retirement Planning: 401(k) plan with both pre-tax and Roth options, and access to a Health Savings Account (HSA) with a monthly company contribution. • Family & Fertility Support: Paid parental leave for birthing and non-birthing parents, plus fertility and family-forming benefits. • Paid Time Off: Unlimited vacation, paid leaves, and 10 company holidays. • Unique Lime Perks: Complimentary use of Lime vehicles in participating cities, a monthly phone allowance, dedicated learning and development days, and access to perks including One Medical, Wellhub, and Headspace.

Apply Now

Similar Jobs

🔥 3 hours ago

Connected Logistics

51 - 200

🔒 Cybersecurity

🏛️ Government

Cybersecurity Assessment & Authorization SME assisting DLA in managing cybersecurity implementation and monitoring. Requires five years of C&A experience and U.S. Citizenship.

🔥 3 hours ago

GitLab

1001 - 5000

🤖 Artificial Intelligence

🏢 Enterprise

☁️ SaaS

Senior Software Security Engineer at GitLab improving abuse detection and prevention systems. Building features for Ruby on Rails platform and collaborating on security enhancements.

🔥 14 hours ago

Alpha Omega

501 - 1000

🏛️ Government

🔒 Cybersecurity

🤖 Artificial Intelligence

Senior Information System Security Officer supporting government clients on cybersecurity portfolios. Developing compliance strategies and ensuring security standards are met across various applications.

🔥 16 hours ago

Information Security Lead overseeing a comprehensive security program at Alloy Therapeutics. Responsible for both technical and governance aspects, ensuring data protection and compliance.

🔥 16 hours ago

Cisco

10,000+ employees

🔧 Hardware

🔐 Security

🏢 Enterprise

Senior Staff Product Manager leading Platform Security at Splunk, focusing on security primitives and cryptography. Driving product strategy and execution for a multi-billion-dollar portfolio.