ClickUp Logo

ClickUp

Senior Security Engineer, App Security

Posted 2 Days Ago
Be an Early Applicant
Hybrid
Canada
Senior level
Hybrid
Canada
Senior level
As a Senior Security Engineer, you will work closely with engineering teams to build secure solutions within ClickUp's productivity platform. Your responsibilities include performing threat modeling, developing security features, building security automation, and ensuring secure product deployment. You are expected to guide and mentor teams on software security practices, analyze security events, and maintain awareness of industry developments.
The summary above was generated by AI

ClickUp is the world’s only all-in-one productivity platform that flexes to the way people want to work. It replaces all individual workplace productivity tools with a single, unified platform that includes project management, document collaboration, whiteboards, spreadsheets, and AI. With our headquarters based in San Diego and a rapidly expanding global presence, we are shaping the future of work. Join our team at ClickUp, one of the fastest-growing SaaS companies worldwide, and help millions of users be more productive - saving them at least one day every week. 🦄

We're looking for a Software Engineer, AppSec for an engineering-focused security team. We are not the prototypical security team: we partner with and embed inside of existing engineering teams at ClickUp.

 

The security team at ClickUp works to build and share technology including defensive security features and functionality, secure infrastructure and operational tools, security response tooling and processes, and security guidelines and guardrails. Our mission: to help the organization move swiftly and securely by giving them secure paved paths. When something slips through anyway, we do our best to prioritize only the vulnerabilities that are actually exploitable, and we recommended fixes that empathize with the realities of development here.

 

You will support this mission by thinking like a developer, recommending solutions they can readily adopt, and implementing our own for areas with heightened risk. Your focus on our product engineers will allow them to build and ship secure products based on Angular, Node.js, and PostgresSQL, all hosted in AWS.

 

You'll be a strategic partner working directly with various engineering teams helping to design, develop and guide teams to secure solutions. We're scaling quickly, and are looking for Security Engineers who aren't afraid of this challenge!

 

The Role:

You'll perform some mix of the following depending on your skillset:

  • Perform threat models, implementation reviews, and security testing; review requirements and designs. (This will be your bread and butter that informs the rest of our work.)
  • Keep up with developments in an area of the stack so your recommendations follow existing patterns.
  • Design, develop and build security features and defenses that protect the entire scope of the ClickUp platform.
  • Design and build tools to help with all stages in security prevention, detection, and response; across the full SDLC from code and test, through to deploy and operate.
  • Embed yourself into existing engineering and product teams, acting as a "security player-coach".
  • Build security automation for and into the ClickUp platform; design and build secure-by-default infrastructure and applications.
  • Monitor and analyze production security events and, as needed, provide in-depth incident analysis.
  • Build relationships with other engineers, product managers, data engineers, operators, and security team members to enable shipping a secure product.

 

Qualifications:

  • Multiple years of experience in technology / software development.
  • Experience with Angular, Node.js, and PostgresSQL; or similar technologies.
  • An ability to identify and provide a basic assessment of security threats.
  • An understanding of security problems, paired with an ability to suggest solutions to software design problems.
  • Cloud and SaaS experience.
  • Ability to mentor others on technical topics, including security.

 

Desirable:

  • Past experience with pushing technical initiatives; team, project, or indirect management of technology.
  • Can facilitate a conversation rather than dictate it.
  • 5+ years of software development experience and 1+ year of security-specific experience.
  • Experience with security tools; SAST, DAST, RASP, dependency checkers, SIEM.
  • 2 years of AWS experience; IAM and least-privilege architectures.

 

If you are a software engineer who is only starting to learn security, please do apply!

 

#LI-REMOTE

#LI-MAV



Unsure if you meet all the qualifications of this job description but are deeply excited about the role? We hire based on ambition, grit, and a passion for improving the way people work. If you think ClickUp is the company for you, we encourage you to apply!

ClickUp was founded on a culture of hard work, consistent growth, and a desire to break norms. We’re a values-driven company and hire based on ambition, merit, and a willingness to do what it takes to succeed. We don’t care where you’re from, what you look like, or who you’re in a relationship with—we hire the best people for the job, and create an environment that supports employees on their journey to do the most exciting work of their lives! ClickUp is an Equal Opportunity Employer, and qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.

ClickUp collects and processes personal data in accordance with applicable data protection laws.

  • If you are a European Job Applicant, see our privacy policy for further details.
  • If you are a Philippine Job Applicant, see our privacy policy and our Philippine Data Privacy Notice for further details.

Please note we are unable to sponsor or take over sponsorship of an employment visa for roles outside of engineering and product at this time. Sponsorship for engineering and product roles is not guaranteed, but is instead based on the business needs for that specific role at that time. Please reach out to the recruiter with any questions.

Top Skills

Angular
Node.js
Postgres

Similar Jobs

16 Days Ago
Hybrid
8 Locations
Senior level
Senior level
Blockchain • Fintech • Mobile • Payments • Software • Financial Services
As a Senior Software Security Engineer, you will work closely with product teams to identify vulnerabilities, design security features, and enhance the security mechanisms for Cash App. You will help implement regulatory data privacy and educate other engineers on security practices, ensuring customer data protection across the product lifecycle.
Top Skills: JavaKotlin
8 Days Ago
Remote
Ottawa, ON, CAN
Mid level
Mid level
Healthtech
As a Lead Security Engineer at Fullscript, you will mentor a security engineering team, implement security best practices, and drive security initiatives throughout the development lifecycle. You will optimize security triage processes and ensure security integration in design and implementation. Your role involves engaging with cross-functional teams and sharing your expertise with the developer community to improve security protocols.
Top Skills: JavaScriptRuby
17 Days Ago
Hybrid
7 Locations
Senior level
Senior level
Automotive • Robotics • Software • Transportation
The Senior Security Engineer at Kodiak will design, build, and monitor the Secure Software Development Life Cycle (SSDLC) to ensure application security in autonomous vehicle technology. Responsibilities include integrating encryption processes, adhering to secure coding principles, conducting application security testing, and collaborating across teams to implement secure designs.
Top Skills: C++

What you need to know about the Ottawa Tech Scene

The capital city of Canada and the nation's fourth-largest urban area, Ottawa has proven a rapidly growing global tech hub. With over 1,800 tech companies, many of which are leaders in their sectors, the city's tech talent now makes up more than 13 percent of its total workforce. This growth is driven not only by the big players like UL Solutions and Dropbox, but also by a thriving startup ecosystem, as new businesses emerge to follow in the footsteps of those that came before them.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account