Enova
Our mission is to help hardworking people get access to fast, trustworthy credit.
Hybrid

Technical Lead, Application Security

Sorry, this job was removed at 12:09 p.m. (MST) on Tuesday, July 28, 2020
Find out who's hiring in Greater Denver Area.
See all Developer + Engineer jobs in Greater Denver Area
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Innovation, collaboration, and success: at OnDeck, We Make It Happen. We’ve changed the way small businesses access financing. With the spirit of a fintech start-up and the stability of a larger organization, OnDeck helps customers achieve their ambitions while leading in the small business lending space. We operate with a one team mindset, supporting each other and celebrating our wins together. If you’re looking for a fast-paced, entrepreneurial, inclusive environment where you can make an impact on our customers and business, OnDeck could be the place for you.

Technology at OnDeck is a mix of building world-class user experiences for our partners and direct customers, data processing to enable underwriting model development and real-time lending decisions, automating operational and compliance workflows, and generating precise money movements and calculations to service our customers. We have an emphasis on scalability, security, reliability and accuracy. 

The OnDeck Security team is looking for a security-minded engineering leader to help secure the financial data of small businesses nation-wide. As a Tech Lead, Application Security, you will integrate tools and analyze the security of OnDeck data, systems, and applications. You enjoy leading the discovery and remediation of security issues, collaboration with development, QA, analytics, IT, and DevOps teams, and the assessment of designs against relevant security threats. This position will provide you with a challenging opportunity to learn and grow.

As a Technical Lead, Application Security at OnDeck, you will:

  • Provide technical leadership in the assessment, design and implementation of application security program
  • Improve and manage the application security program by developing partnerships with tech and product teams
  • Perform threat modeling and security architecture reviews
  • Guide product and technology teams to integrate security into their software development lifecycle
  • Conduct static code reviews and dynamic security assessments
  • Effectively deliver technical debriefs to stakeholders including technical staff, stakeholders and leaders
  • Perform and oversee application security vulnerability assessments, penetration testing and provide vulnerability remediation guidance
  • Develops scripts, tools, methodologies and best practices to improve team capabilities while articulating business risks of technical vulnerabilities to various stakeholders
  • Provide security training and outreach to internal development teams

Qualifications to make it happen: 

Required

  • 8+ years of experience with any combinations of the following: dynamic application testing, threat modeling experience, secure code review, identity management and authentication, software development, cryptography.
  • Have a strong knowledge of building security into continuous integration and delivery (CI/CD) pipeline.
  • Use a risk-based approach, advocate for and help prioritize remediation of security findings and develop/report metrics measuring the state of application security program.
  • Managerial experience, ideally having experience managing remote employees
  • Development experience with Java and JavaScript. Ruby and Angular a plus.
  • Experience with application security tools as OWASP ZAP, Portswigger Burp, IBM AppScan, HP WebInspect, and Acunetix.
  • Know and recognize application security issues
  • You leverage industry security standards and organizations such as NIST

Preferred

  • Publications or Tech Talks at conferences or meetups focused on Security.
  • Experience working in DevSecOps and Security Automation.
  • AWS Security experience or practices.
  • Experience with securing data in Amazon Web Services (AWS), Salesforce, Postgres, and MongoDB is a plus
  • You reject the idea of security being a blocker, and actively enjoy collaborating with colleagues across the entire engineering organization.
  • You want to build things, not just break them

About OnDeck:

OnDeck is the largest online small business lender in the U.S. Since 2007, we’ve issued over $12 billion in loans for many business needs including inventory purchase, equipment acquisition, hiring, and general corporate purposes. Serving more than 700 industries throughout the country, OnDeck has been trusted by over 100,000 small businesses by providing them with a term loan or line of credit to help them build a growing and thriving enterprise.

Click here for a glimpse inside our offices

At OnDeck, it’s We Before Me. We support each other and we love seeing people succeed. That’s why we offer a competitive and comprehensive benefit program with a variety of options and opportunities. We offer:

  • Flexible Paid Time Off; Paid Sick Days; Paid Holidays; Paid Birthday
  • Comprehensive Healthcare (Medical/Dental/Vision/Life Insurance)
  • Wellness Subsidy and Mental Health Coaches
  • Voluntary Auto/Home/Pet Insurance
  • Educational Reimbursement; Flexible Working Arrangements
  • 401k Matching, Loan Consolidation, Employee Stock Purchase Program
  • Paid Parental Leave and Sabbaticals
  • Affinity Groups and Volunteer Events

We are going to ask you to talk about your accomplishments. Here are some of ours: 

  • Built in Colorado, Top 100 Digital Companies in Colorado, 2015, 2016, 2017
  • Built in NYC’s 100 Best Places to Work, 2019
  • Colorado SHRM Best Companies to Work For in Colorado, 2015
  • Crain’s New York Best Places to Work, 2013, 2014, 2015
  • Crain’s New York Business Fast 50, 2013, 2014, 2016, 2017
  • Denver Business Journal Largest Technology Employers in Denver, 2019
  • Denver Business Journal Best Places to Work, 2019
  • FinTech Breakthrough Award – Best Overall LendTech Company, 2018
  • Fortune 50 Best Workplaces for Diversity, 2016
  • Fortune 50 Best Small and Medium Companies to Work For, 2016
  • Fortune 30 Best Workplaces in Finance and Insurance, 2016
  • Fortune.com and Great Place to Work 100 Best Workplaces for Millennials, 2015
  • Fortune/Great Place To Work Great Rated! People’s Picks: 20 Great Workplaces in Financial Services, 2015
  • Forbes’ America’s Most Promising Companies, 2013, 2014
  • Great Place to Work Certification, 2017, 2018, 2019
  • Inc. 500|5000, 2013, 2014
  • Inc. Hire Power, 2013
  • Lending Tree’s Top Rated Customer Satisfaction, Q1 2018
  • Selling Power Magazine Best Company to Sell For, 2013, 2014, 2015, 2016, 2017, 2018, 2019
  • US News & World Report, “Best Unsecured Business Loans of 2018” – Best for Term Loans
  • Washington Post Top Places to Work, 2019
  • WorldatWork, 2017 Seal of Distinction
  • TalentDesk’s Best Large Companies for Computer Science Jobs in Arlington, Virginia: #1, 2019
  • TalentDesk’s Best Companies for Customer Service Jobs in Denver, Colorado: #1, 2019
  • TalentDesk’s Best Companies for Quality Assurance Jobs in Denver, Colorado: #1, 2019

As part of our dedication to maintaining an inclusive and diverse workforce, OnDeck provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, OnDeck complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

OnDeck expressly prohibits any form of workplace harassment based on race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. Improper interference with the ability of OnDeck’s employees to perform their job duties may result in discipline up to and including discharge.

**No external recruiters or agents, please.**

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are Enova Perks + Benefits

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
Pair programming
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity manifesto
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Employees have the option to set aside pre-tax dollars to pay for eligible Medical, Dental and Vision expenses as well as eligible child care expenses.
Disability insurance
Our short-term plan provides a level of continued income in the event you become disabled and cannot work. Should your disability extend past 26 weeks, LTD kicks in at 60% of base monthly earnings.
Dental insurance
Employees can choose from two dental plans including one that is offered at no cost for employee-only coverage.
Vision insurance
Our Vision plan provides affordable eye care and discounts to cover routine eye exams, prescription eyeglasses or contact lenses.
Health insurance
We offer employees flexibility to choose from several comprehensive medical plans.
Life insurance
Our basic life insurance plan is a core benefit provided by the company at no cost to you. You can purchase additional life insurance for yourself, spouse or domestic partner and eligible dependents.
Pet insurance
You have the option to elect pet insurance which includes coverage for veterinary expenses related to accidents and illnesses.
Wellness programs
Team workouts
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
We provide employees with a 401(k) matching plan managed by Fidelity. We match 50% of contributions up to 3% of an employee's annual gross pay.
Company equity
Performance bonus
Charitable contribution matching
Child Care & Parental Leave Benefits
Childcare benefits
Generous parental leave
Family medical leave
Return-to-work program post parental leave
Company sponsored family events
Vacation & Time Off Benefits
Generous PTO
Paid volunteer time
Sabbatical
Eligible employees get 20 days of paid sabbatical after their first 5 years of working at the company.
Paid holidays
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Relocation assistance
Fitness stipend
Home-office stipend for remote employees
Onsite gym
Professional Development Benefits
Job training & conferences
Each department gets a set budget every year to send their own team members to job training and conferences relevant to their job and development.
Tuition reimbursement
Team members are eligible to apply for tuition reimbursement for various career and professional development opportunities.
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend
Online course subscriptions available
Customized development tracks
Paid industry certifications

Additional Perks + Benefits

Sabbatical program • Recognition programs • Commuting reimbursement • Monthly social events • Discounted gym memberships • Pet insurance

More Jobs at Enova

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about EnovaFind similar jobs like this