BetterHelp→
Senior Security Engineer, Applications at BetterHelp · Mountain…
InternshipHybridFull-timeMountain View, CA$130k–$185k/yr
Skills
web application securitycode reviewsecurity architecturepentestingbug bounty programsweb security vulnerabilitiesweb application pentesting toolsnetworking conceptsowasp top 10security automationsphpreactnext.jsbash scriptingawskubernetesai awarenessthreat modeling
Job Description
Summary: BetterHelp is on a mission to remove barriers to therapy and make mental health care more accessible. As a Senior Security Engineer on the Applications Team, you will focus on enhancing the security of applications, collaborating with various teams to identify vulnerabilities and implement secure coding practices.
Responsibilities:
- Work with a nimble passionate security team, collaborating with development and product
- Conduct vulnerability triage: handle internal and external vulnerability reports, and more importantly: go beyond investigating and write fixes yourself
- Review code and help make decisions about secure coding decisions
- Review new product features to ensure they are designed with security in mind
- Collaborate with other developers and teams for long term security success
- Code solutions for preventative measures and generating alerts
- Use your detective work to get to the AH-HA! moment when you find and replicate the root cause of an issue and figure out how to fix it
- You will care and be involved in our product, mission, and success - way beyond checking off tasks
Required Qualifications:
- 5+ years of experience in web application security
- Strong experience with code review, security reviews, security architecture, pentesting, and bug bounty programs
- Experience working in full-stack projects
- Experience with discovering and fixing common web security vulnerabilities
- Experience using web application pentesting tools (e.g. Burp Suite)
- Basic understanding of networking concepts (DNS, TCP/IP, VPNs)
- Able to explain complex ideas either verbally or in writing to a mixture of audiences
- Knowledge and understanding of the OWASP Top 10
- Experience creating security automations with GitHub Actions or other methods
Preferred Qualifications:
- Experience coding in PHP and working with React/Next.js
- Experience using scripting, using regex, and writing bash scripts
- Experience with applications deployed in AWS & Kubernetes
- Awareness of AI and LLMs, and how they are used in consumer products
- Experience using AI and LLMs in security research
- Experience with threat modeling
Required Skills: Web application security, Code review, Security architecture, Pentesting
Important Skills: Bug bounty programs, Web security vulnerabilities, Web application pentesting tools, Networking concepts, OWASP Top 10, Security automations
Nice-to-Have Skills: PHP, React, Next.js, Bash scripting, AWS, Kubernetes, AI awareness, Threat modeling
Benefits: Remote work with regular in-person bonding experiences sponsored by the company, Competitive compensation, Holistic perks program (including free therapy, employee wellness, and more), Excellent health, dental, and vision coverage, 401k benefits with employer matching contribution, The chance to build something that changes lives – and that people love, Any piece of hardware or software that will make you happy and productive, An awesome community of co-workers
Benefits
Remote work with regular in-person bonding experiences sponsored by the company
Competitive compensation
Holistic perks program (including free therapy, employee wellness, and more)
Excellent health, dental, and vision coverage
401k benefits with employer matching contribution
The chance to build something that changes lives – and that people love
Any piece of hardware or software that will make you happy and productive
An awesome community of co-workers