Full-Time

Senior Security Engineer

Application & Product Security

Posted on 10/31/2025

CaptivateIQ

CaptivateIQ

201-500 employees

Automates real-time sales commission calculations

Compensation Overview

$154.5k - $197.8k/yr

+

Nashville, TN, USA + 2 more

More locations: Toronto, ON, Canada | Raleigh, NC, USA

Remote

Category
IT & Security (4)
, , ,
Required Skills
Python
Requirements
  • 7+ years of experience in a security engineer or related role, including 4+ years specializing in web application, API, and product security.
  • Deep expertise securing multi-tenant SaaS platforms and features.
  • Strong communication and ability to influence software engineers and product managers.
  • Advanced experience conducting penetration tests, code reviews, and vulnerability assessments.
  • Expert knowledge of OWASP Top 10, web application and API security, and common vulnerability classes with practical remediation strategies.
  • Hands-on experience with AppSec tooling (SAST, DAST, SCA) integrated into CI/CD pipelines.
  • Strong programming and scripting skills (Python preferred) and ability to influence secure coding practices.
  • Proven ability to lead incident response for application-layer security events.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001) and secure SDLC practices.
  • Knowledge of privacy-by-design principles and data security in SaaS environments.
  • Awareness of emerging AI/ML security risks and related countermeasures.
Responsibilities
  • Threat Modeling & Architecture Reviews Mature and scale a modern threat modeling program across products and services. Enable secure by design architectures in collaboration with Engineering teams.
  • Offensive Security Testing Conduct penetration tests (white-box and black-box) for web applications and APIs. Perform dynamic (DAST), static (SAST), and software composition (SCA) analysis. Simulate adversary attack scenarios to validate controls and identify gaps.
  • Secure SDLC Integration Embed security into every stage of development; implement automated security tooling in CI/CD pipelines.
  • Vulnerability Management Triage and prioritize application-layer vulnerabilities and guide engineering teams through remediation.
  • Developer Enablemen t Deliver secure development and coding training; create resources to reduce recurring vulnerabilities.
  • Bug Bounty Management Oversee Bug Bounty program, validate findings, and ensure timely resolution.
  • Incident Response Leadership Lead investigations for application-layer security incidents and conduct post-incident analysis.
  • Compliance Enablement Support audits, technical evidence collection, and control design for SOC 2, ISO 27001, and privacy-by-design requirements.
  • Customer Trust Contribute to customer security assessments, penetration test reports, and security documentation.
Desired Qualifications
  • Certifications such as OSCP, GCIH, GWAPT, or CISSP.
  • Familiarity with security frameworks such as NIST CSF, MITRE ATT&CK, OWASP ASVS, or ISO 27001.
  • Experience with commercial security tools such as EDR, SIEM, CSPM, CNAPP, vulnerability scanners, bug bounty platforms, WAFs, or compliance automation platforms.
  • Prior experience driving security engineering for a SaaS-based company.
  • Experience leveraging automation or AI/ML tools to improve secure development, detection, incident response, or code analysis workflows.

CaptivateIQ provides a sales commission platform that automates and streamlines commission calculations for sales teams. It connects data from multiple sources, calculates commissions in real time as data changes, and eliminates manual data entry. Its spreadsheet-like, no-code interface makes it easy for teams to create customizable commission plans and reports. Its goal is to help sales-driven organizations align incentives, improve transparency, and increase operational efficiency by making commission management scalable.

Company Size

201-500

Company Stage

Series C

Total Funding

$159.1M

Headquarters

San Francisco, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Processes 8 trillion calculations monthly, scaling for enterprises.
  • $165M funding from Sequoia, Accel fuels expansion to 800 customers.
  • AI features forecast quotas, detect anomalies, enhancing performance.

What critics are saying

  • Xactly locks Fortune 500 clients, blocking CaptivateIQ enterprise expansion.
  • Salesforce native ICM captures users in 12-18 months.
  • Varicent undercuts pricing, diverts mid-market deals in 6-12 months.

What makes CaptivateIQ unique

  • Guided Plan Builder enables no-code commission plan design launched June 3, 2025.
  • Quotient redesigns commission admin experience unveiled December 12, 2024.
  • SmartGrid ELT ingests data real-time from any source for single truth.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

401(k) Company Match

Flexible Work Hours

Home Office Stipend

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

-2%
Martechvibe
Aug 18th, 2025
CaptivateIQ Merges Sales Planning, Incentives

CaptivateIQ, a sales performance management solution, launched the next generation of its platform: combining incentive compensation management with sales planning capabilities into one, AI-infused workspace.

PR Newswire
Jun 3rd, 2025
Captivateiq Introduces Guided Plan Builder To Make Commission Plan Management Faster And Easier

New no-code experience eliminates the tradeoff between flexibility and ease for incentive compensation teamsSAN FRANCISCO, June 3, 2025 /PRNewswire/ -- CaptivateIQ, a leading sales performance management solution, today announced the launch of its Guided Plan Builder. This major product innovation for CaptivateIQ's Incentives product helps lower the cost of managing incentive compensation through faster time to value, in-house ownership and a reduced admin learning curve.For too long, organizations have been forced to choose between manual spreadsheets, which offer flexibility but are error-prone and hard to scale, or rigid platforms that make change difficult. This Guided Plan Builder enables compensation leaders to design commission plans through a point-and-click, visual experience, without writing code or relying on technical teams."Comp teams have spent years stuck between spreadsheets that break and platforms that box them in," said Mark Schopmeyer, co-CEO of CaptivateIQ. "We didn't want teams to have to compromise between ease and flexibility, so we built Guided Plan Builder to deliver both: intuitive plan building backed by a robust modeling engine."Key capabilities include:Plan Credits Wizard: Quickly filter transactions to the right payees and period with guided stepsQuickly filter transactions to the right payees and period with guided steps Pre-Built Calculation Templates: Apply blueprints for common calculation components like flat, tiered, and conditional rates to build plans and payout components fasterApply blueprints for common calculation components like flat, tiered, and conditional rates to build plans and payout components faster Full Plan Customizability: Apply advanced logic for when plans get more complexApply advanced logic for when plans get more complex Plan Visualizer: Easily understand how data flows through your plan structure in a clear, graphical viewLong recognized for its powerful, flexible modeling engine, CaptivateIQ's Guided Plan Builder is now taking usability a step further—giving compensation teams a seamless, end-to-end experience that combines robust logic with approachable design. Now, incentive comp teams no longer need to choose between easy and flexible.To learn more about the new experience or request a personalized demo, visit this page.About CaptivateIQCaptivateIQ is the leading Sales Performance Management solution, trusted by customers including Affirm, Boston Scientific, and Gong. With solutions for Sales Planning and Incentives, they help revenue teams automate processes, hit revenue targets, and adapt with business change, ultimately driving efficient growth

PR Newswire
Apr 23rd, 2025
CaptivateIQ Launches New Solution to Power Performance-based Bonuses

CaptivateIQ launches new solution to power performance-based bonuses.

The Prescott Times
Mar 11th, 2025
CaptivateIQ Named a Leader in Incentive Compensation for Sales Performance Management

One such customer, Tatiana Silverman, VP, Compensation & HRIS at Transportation Insight, praised CaptivateIQ's combination of product innovation and customer support: "It's no surprise that CaptivateIQ was named a Leader.

CaptivateIQ
Mar 11th, 2025
CaptivateIQ Makes Waves with Position as a Leader in Forrester Report

CaptivateIQ makes waves with position as a Leader in Forrester report.

INACTIVE