Over the coming years, biotech will fundamentally rewrite the way we live. Gene editing and cell therapy are dramatically changing how we treat cancer and other major illnesses. Biofuels and biomaterials are transforming the cars we drive, the clothes we wear, and the makeup of everyday objects. Crop science and synthetic biology are producing sustainable and ethical food. Benchlings mission is to accelerate the research that propels us towards this reality, and magnify its impact, through modern software.
Every day, scientists around the world use Benchlings applications, platform, & analytics in their efforts to solve humanitys most pressing problems. For these scientists, Benchling is the central technology they use to conduct their research. Our customers include pharmaceutical giants, leading biotechs, and the worlds most renowned research institutes.
As an Application Security Engineer at Benchling youll be joining a team responsible for building a best-in-class security program from the ground up. Our focus is on providing value to the organization by emphasizing real world security and embracing automation to keep up with the company as we experience hyper-growth. Were looking for engineers who are excited to apply their expertise to our mission of securing some of society's most sensitive data
WHAT YOU WILL WORK ON
- Partnering with both the Product Design and Software Engineering organization's security and privacy initiatives, leading security design reviews, and threat modeling.
- Performing black-box and grey-box penetration testing of our own and partners services.
- Performing code reviews of our own and partners services and apps including SaaS, PaaS, and mobile.
- Researching new attack vectors and techniques relevant to our space and present findings to both internal and external audiences.
- Collaborating with engineers on the best ways to mitigate vulnerabilities and reduce risk.
- Participating in our incident response and vulnerability remediation efforts.
- Integrating external and internal security tools and automation into development and build environments
- Developing lightweight SDLC processes to embed into Product Design and Software Engineering workflows.
- Develop secure coding practices and train engineering teams.
- Interface with customers security teams when they are scoping and performing security assessments.
- Helping to rapidly scale our team. As a member of the security team, you'll be an integral part of how we mature our own tooling, best practices, engineering processes, and hiring.
- 5-10+ years work experience in an application security or product security role including experience with code reviews, pentesting, and ideally threat modeling.
- Strong communicator with the ability to translate technical security requirements and risks into terms that anyone can understand
- In-depth experience finding AND fixing web application security vulnerabilities including those found in the OWASP Top 10 and CWE Top 25.
- Strong, general knowledge of the browser security model, modern network security, and cloud (AWS ideally) security.
- Experience with vulnerability management and risk assessment processes.
- Technical leadership skills; you enjoy being a tech lead, mentoring technologists, and evangelizing security and privacy
- Comfortable with complexity in the short term but can build towards simplicity in the long term
Benchling welcomes everyone. We believe every member of our team enriches our diversity and inclusion by broadening our ways of problem-solving for future challenges. Even if you don't meet 100% of the qualifications for this job, we strongly encourage you to apply.
- Admit mistakes and shortcomings
- Deliver results
- Disagree and commit
- Obsess over customers
- Rely on work ethic
- Show empathy
- Recruit and develop the best
- Sweat the details
- Think and communicate clearly
- Unite around the mission
PERKS AND BENEFITS
- Work with a talented yet humble team
- Competitive compensation & equity package
- Quarterly mental health days
- Weekly virtual social events, and annual company retreats
- 401k, Medical, dental, and vision insurance (US Employees Only)
- Monthly health & wellness stipend (Currently US Employees Only)
- Yearly educational stipend (Currently US Employees Only)
- To support remote work conditions, Benchling provides each employee a one-time stipend of $1,000(USD) upon commencing employment, and additional discounted employee purchase plans for home-office equipment.
In following best practices and safety protocols, all Benchling employees are expected to work remotely until we are further advised that it is safe for employees to resume work in their respective office locations.
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We also consider for employment qualified applicants with arrest and conviction records, consistent with applicable federal, state and local law, including but not limited to the San Francisco Fair Chance Ordinance.