Simplify Logo

Full-Time

Senior Application Security Engineer

Confirmed live in the last 24 hours

Box

Box

1,001-5,000 employees

Cloud-based content management and collaboration solutions

Enterprise Software
AI & Machine Learning

Compensation Overview

$154k - $226.5kAnnually

+ Equity + Benefits

Senior

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Python
Node.js
Java
Requirements
  • 5+ years of experience with creating secure coding requirements, conducting threat models and pen testing software end-to-end
  • Expert in determining the severity of a vulnerability and their impact to the business
  • Expert with common security testing methodologies, including fuzz testing and using tools like Burp Suite
  • Experience with the process of developing, building, and shipping secure code
  • Understand secure engineering best practices, can articulate problem statements and propose solutions to both technically savvy and non-technical audiences
  • Experience with multiple languages such as Java, React, Node JS, PHP, Scala, C and/or Python to perform secure code reviews
  • Understand how to detect and prioritize Front End, API's, Microservices and Container vulnerabilities
  • Strong understanding of past, current, and emerging security exploits and the TTPs (tactics, techniques, and procedures) threat actor groups leverage
  • Ability to communicate and report to various levels of technical and non technical stakeholders
Responsibilities
  • Conduct product/feature level Design Reviews, Code Reviews, Threat Modeling, Penetration Testing and Conducing Vulnerability Risk Analysis
  • Lead manual security reviews and create secure coding requirements
  • Discover vulnerabilities through web and mobile penetration testing
  • Evaluate products for how a threat actor could leverage user-facing flows for malicious activity
  • Deliver reports on completed tests and document technical issues identified during the assessments
  • Collaborate with Product, Engineering and broader security teams to provide recommendations for solutions focused on decreasing business risks
  • Support the Bug Bounty/VDP program through triaging submissions and proposing remediations
  • Identify and maintain standards and procedures around the use of open source software

Box provides cloud-based content management and collaboration solutions that enable businesses to securely manage, share, and collaborate on their content. The platform offers features such as secure file storage, sharing, and collaboration tools, along with advanced functionalities like Box AI for Notes and Box AI for Documents, which utilize artificial intelligence to improve productivity by providing instant answers and content creation capabilities. Box differentiates itself from competitors through its focus on customer-centricity and tailored subscription plans that cater to various industries and business sizes. The company's goal is to transform the way people work together by offering a simple, secure, and efficient cloud content management system.

Company Stage

IPO

Total Funding

$1.2B

Headquarters

Redwood City, California

Founded

2005

Growth & Insights
Headcount

6 month growth

8%

1 year growth

10%

2 year growth

20%
Simplify Jobs

Simplify's Take

What believers are saying

  • Box's recognition as one of the 100 Best Companies to Work For® in 2024 highlights its commitment to fostering an inclusive and supportive work environment.
  • Strategic partnerships, such as the integration with Microsoft Azure OpenAI Service, enhance Box's AI capabilities and offer advanced solutions to its clients.
  • The appointment of experienced leaders like Steve Murphy to the Board of Directors brings valuable expertise and guidance to drive the company's growth.

What critics are saying

  • The competitive landscape of content management and collaboration tools is intense, with major players like Google Drive and Microsoft OneDrive posing significant challenges.
  • The integration of advanced AI tools requires continuous innovation and investment, which could strain resources and impact profitability.

What makes Box unique

  • Box's integration of AI tools like Box AI for Notes and Documents sets it apart by enhancing productivity through instant answers and content creation capabilities.
  • The company's strong emphasis on security and compliance, particularly in sectors like healthcare, makes it a trusted partner for organizations handling sensitive data.
  • Box's global presence, with significant operations in APAC, allows it to cater to a diverse range of clients, from small businesses to large enterprises and government agencies.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health and Wellness

Family Support

Generous Time Off

Financial Benefits

Community

Evolving Workplace