Full-Time

Staff Product Security Engineer

Confirmed live in the last 24 hours

Navan

Navan

1,001-5,000 employees

Travel and expense management solution for enterprises

Data & Analytics
Enterprise Software
Fintech

Compensation Overview

$150k - $265kAnnually

+ Base Salary + Target Incentive Compensation

Senior, Expert

Company Does Not Provide H1B Sponsorship

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
JavaScript
Git
Docker
Microservices
AWS
JIRA
Jenkins
Terraform
AngularJS
HTML/CSS
Hibernate

You match the following Navan's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • Proven experience performing threat modeling and architecture reviews for complex applications.
  • Proven experience delivering critical org-wide product security initiatives.
  • Proven experience performing application, cloud and mobile penetration testing in high risk environments like financial or healthcare companies.
  • 8-10 years of Technical Product Security related experience around SSDLC tooling, automation, remediation advisory, security testing, threat modeling/attack surface analysis.
  • Ability to execute in multifaceted and highly technical organizations.
  • Ability to provide pragmatic security advice for web applications, mobile applications, and cloud software.
  • Experience working in Agile development with experience in technologies such as: Cloud environment (AWS, or similar), Application security testing tools (SAST, DAST, IAST, SCA, or similar), Infrastructure as code (Terraform, or similar), Java Spring Framework (3+ years), Hibernate or similar ORM technologies, JavaScript/CSS, and Angular, Containers (Docker, Kubernetes, or similar), Continuous integration (Jenkins, Github Actions or similar), Integration of Security testing tools into CI pipelines, Defect tracking (Jira, or similar), Source code management (GitHub, or similar).
  • In-depth knowledge of common application & network protocols, cryptographic primitives, authentication & authorization protocols, and common security threats, such as attack techniques, evasive techniques, and preventative & defensive methods.
  • Deep knowledge of cloud operational models and secure SaaS architecture in a containerized microservices world.
Responsibilities
  • Act as the tech lead for high-priority product security initiatives, and ensure timely delivery of impactful initiatives.
  • Be a key advisor to the overall strategy and roadmap of the Product Security Program.
  • Drive key initiatives like Supply Chain Security, Authentication, and Authorization improvements.
  • Participate in expanding/maturing the Navan S-SDLC program.
  • Review product designs for security defects, perform threat modeling and recommend remediations.
  • Work with engineers to identify the tradeoffs of different solutions and recommend the ideal design to meet security requirements.
  • Design and develop security tools and processes to be leveraged by development teams.
  • Work closely with engineering to sustain processes and/or convert manual integrations to automated pipeline activities.
  • Assist in developing custom Security as Code solutions.
  • Provide training, guidance, and assistance to development teams early in the SSDLC.
  • Cultivate security ownership in the product teams.
  • Bring visibility to product/application vulnerabilities in a consistent manner to enable appropriate prioritization and remediation.
  • Help build the Red Team and PSIRT functions.
Desired Qualifications
  • Published contributions to the security community.
  • Deep understanding of browser security and modern JavaScript frameworks.
  • Knowledge of compliance requirements for industry-standard certifications like PCI DSS, SOC2, HIPAA, and FedRAMP.
  • Experience working in small teams and delivering outsized impact.

Navan provides a travel and expense management platform tailored for enterprises. The platform enables users to efficiently book, view, and manage their business travel and expenses through a cloud-based and mobile interface. It incorporates AI technology to streamline processes and offers features like Navan Rewards, which incentivizes employees to save on travel costs by providing rewards for cost-effective decisions. Additionally, the Navan card integrates expense management directly into the travel booking experience. Unlike many competitors, Navan focuses on creating a supportive environment for its users by emphasizing diversity, equity, and inclusion within its workforce. The company's goal is to enhance human connections, improve operational efficiency for businesses, and empower better decision-making through data and insights.

Company Stage

Debt Financing

Total Funding

$1B

Headquarters

Palo Alto, California

Founded

2015

Growth & Insights
Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

0%
Simplify Jobs

Simplify's Take

What believers are saying

  • Navan's acquisition of Tripeur boosts its presence in the Indian market.
  • Navan Connect's expansion across Europe enhances its global reach.
  • Unified finance suite with Rho offers comprehensive travel and expense management.

What critics are saying

  • Brex's enhanced solutions may attract Navan's financial management clients.
  • Integration challenges with Tripeur could delay expected synergies.
  • Competition in Europe may hinder Navan Connect's market penetration.

What makes Navan unique

  • Navan integrates AI, cloud, and mobile for seamless travel and expense management.
  • Navan Rewards incentivizes cost-effective travel decisions, enhancing user engagement.
  • Navan Connect supports global expense management with existing corporate cards.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Vacation: Take time off when you need it, just work with your manager.

Healthcare: Medical, dental, and vision for you and your family.

Commuter benefits: Pre-tax transit dollars, $70 a month to ease your commute.

Parental leave: All parents (birthing and non-birthing) are eligible for paid leave.

Health and Wellness: Annual wellness stipend and access to a full spectrum of resources.

Fuel for Connection: We provide in-office snacks and lunches*, fostering community and in-person connections.

Pet Friendly: Pet insurance with preferred rates and dog friendly offices*.

401k: We care about your future and offer a 401k retirement plan program and company match.

IATAN: Employees can register and receive access to thousands of travel related discounts.

Connectivity Allowance: We support our employees ability to work seamlessly and confidently while from home and offer a bi-weekly stipend

Learning & Development: Annual Learning and Development allowance to propel professional growth