companyiHerb Inc. logo

Application Security Engineer

iHerb Inc.United States of America - Remote / Home Office
Remote Full-time $85K/yr - $173.8K/yr

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Experience

Qualifications

Knowledge, Skills and Abilities: Required: Strong technical foundation in application security. Deep understanding of common application and infrastructure security vulnerabilities and mitigation strategies (e.g., OWASP Top 10, CWE 25). Experience in implementing Secure Development Lifecycle processes and automation in a DevOps environment. Familiarity with large-scale web applications and microservices, including API design, access management, authorization, authentication, and data protection/encryption. Exceptional problem-solving, critical thinking, collaboration, and communication skills.

About the job

Job Summary:

The Application Security Engineer will play a pivotal role in enhancing our Secure Development Lifecycle assurance processes and security automation technologies. This individual will spearhead the security hardening strategy across our product offerings while responding to both current and emerging security threats. This position is integral to our Product Security team, collaborating with development teams worldwide to define innovative security capabilities and partnering with organizational leaders to implement comprehensive security initiatives.

Job Expectations:

  • Lead cross-functional projects to establish advanced security development lifecycle practices.

  • Conduct security design reviews and threat modeling for both new and existing services at iHerb.

  • Assess, prototype, implement, and manage security-focused tools and services.

  • Create new secure architecture standards, frameworks, and patterns that span multiple layers.

  • Analyze emerging security threats relevant to iHerb and proactively develop centralized mitigations.

  • Evaluate, prototype, implement, and operate security tools and services (DAST, SAST, SCA, etc.).

  • Maintain an up-to-date understanding of current security threats and operational best practices.

  • Participate in our security assessment, penetration testing, and bug bounty programs.

  • Engage in security incident response activities.

The responsibilities listed above are intended to provide a general overview of the role and are not exhaustive. Additional duties may be assigned as necessary.

About iHerb Inc.

iHerb is a leading online retailer offering a vast selection of natural products and supplements. Our commitment to quality and customer satisfaction has made us a trusted name in the industry. Join us in making a positive impact on health and wellness worldwide.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.