FusionAuth Logo

FusionAuth

Senior Application Security Engineer

Posted 25 Days Ago
Be an Early Applicant
Hybrid
Denver, CO
140K-200K
Senior level
Hybrid
Denver, CO
140K-200K
Senior level
The Senior Application Security Engineer will ensure application security by developing secure code, conducting threat modeling, and engaging in security audits and customer support.
The summary above was generated by AI

Job Title: Senior Application Security Engineer

Location: Denver, CO (Hybrid)


About FusionAuth

FusionAuth is a fast-growing startup and leading provider of customer identity and access management (CIAM) software headquartered in Denver, Colorado. Our mission is to make authentication and authorization simple and secure for every developer.  Our product helps businesses securely manage customer identities and access, ensuring a seamless and safe user experience for some of the largest brands in the world. We are committed to delivering exceptional value and satisfaction to our clients through top-notch service and support.  With a great team and strong investors, we are expanding our team to help accelerate our growth and take FusionAuth to the next level.

Job Summary

We are seeking a Senior Application Security Engineer to join our engineering team. In this role, you will be responsible for ensuring that our applications and infrastructure meet stringent security standards. Additionally, you will be instrumental in fostering a security-centric culture throughout the engineering teams. To excel in this position, you should possess a creative and quantitative mindset, along with a deep understanding of secure coding practices. A strong passion for authentication, authorization, and user management is essential. Prior experience in security-focused roles or practices, such as penetration testing (PEN testing), bug bounties, or similar endeavors, will be highly valued. This position is based in the Broomfield, CO area.


Responsibilities

  • Participate in threat modeling, code reviews, and security audits to strengthen our applications against vulnerabilities.
  • Manage our bug bounty program by validating submissions and assessing awards.
  • Research and integrate security tools into our development processes and pipelines.
  • Design and implement new features with an emphasis on secure coding practices and risk mitigation.
  • Write and maintain extensive, security-focused tests, including unit, integration, and vulnerability tests.
  • Maintain our software with bug fixes, enhancements, and security patches.
  • Produce clear, high-quality documentation for new features and security protocols.
  • Contribute to platform roadmap planning and software architecture with an application security perspective, including prioritization of security-related bugfixes.
  • Advocate for best practices in security within the Engineering organization, including developing training curricula on secure coding practices.


Qualifications Required

  • 7+ years of professional software development experience with a significant focus on application security.
  • Bachelor’s degree in Computer Science or equivalent practical experience with a strong understanding of secure software development principles.
  • Expertise in Java web-application development and security.
  • Proven experience in roles with security responsibilities, such as PEN testing, bug bounties, or similar security assessments.
  • Highly proficient in object-oriented design and implementation with a secure development mindset.
  • Strong understanding of the full web stack, including HTTP, TCP/IP, and REST, with an awareness of potential vulnerabilities in these areas.
  • Experience building highly available, high-performance, scalable, and secure applications.
  • Expertise in developing multi-threaded, API-first applications with secure data handling practices.
  • In-depth knowledge of unit, integration, and vulnerability testing to ensure the robustness of our applications.
  • Experience across the stack, from cloud infrastructure to front-end security practices.

All About You

We believe the following qualities will enhance your success in this role:

  • You are analytical and data-driven, using metrics to understand and mitigate security risks.
  • You have an interest in the authentication and authorization space, with a focus on security.
  • You bring a strong yet flexible approach to security, ready to adapt as the landscape changes.
  • You quickly learn new technologies and security practices.
  • You’re excited about contributing to our open-source projects and building a secure ecosystem.
  • You thrive in a startup environment and bring a proactive, security-focused mindset to your work.


Compensation

  • $140 - 200k expected base salary range*

Top Skills

Application Security
Cloud Infrastructure
HTTP
Multi-Threaded Applications
Rest
Secure Coding Practices
Tcp/Ip
Vulnerability Testing
HQ

FusionAuth Westminster, Colorado, USA Office

11080 Circle Point Rd Suite 405. , Westminster, CO , United States, 80020

Similar Jobs at FusionAuth

9 Days Ago
Hybrid
Denver, CO, USA
140K-170K
Senior level
140K-170K
Senior level
Security • Software • Cybersecurity
The Senior Developer Advocate will create content to educate developers on CIAM, gather feedback, and improve user experience while building partnerships.
Top Skills: Access ManagementAuthenticationAuthorizationIdentity ManagementSoftware Development
9 Days Ago
Hybrid
Denver, CO, USA
140K-180K Annually
Senior level
140K-180K Annually
Senior level
Security • Software • Cybersecurity
The Senior Java Engineer will write secure code, develop new features, maintain software, and support customers while contributing to product improvement.
Top Skills: HTTPJavaRestTcp/Ip

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account