About the Role
Beacon is seeking its first dedicated Application Security Engineer to establish the product security strategy and initiate program development. This role will span both Beacon's internal engineering and its portfolio companies' products, requiring close collaboration with development teams. You will embed within these teams, influencing design and planning, and own the technical roadmap for product security as Beacon expands.
Responsibilities
- Lead threat modeling and security architecture review for new product work and platform initiatives.
- Define standards for authentication, authorization, encryption, and tenant isolation.
- Own the product security review of newly acquired codebases and cloud environments.
- Establish baseline security posture, identify material risks, and define remediation paths for acquisitions.
- Perform secure code review, focusing on authorization and business logic flaws missed by automated tools.
- Manage the external penetration testing partner and drive remediation of identified vulnerabilities.
- Assess AI features across products, including agent architectures, model/tool access, and delegated credentials.
- Own the end-to-end vulnerability management program, including intake, severity, prioritization, remediation SLAs, and reporting.
- Drive vulnerability fixes through engineering teams, ensuring sustainable remediation.
- Own the standard for SAST, DAST, SCA, and secrets scanning, and their CI/CD integration across the portfolio.
- Build automation for routine fix PRs, dependency remediation, and findings routing.
- Own the security of internal tools, including their access to credentials, source code, and production systems.
- Write secure coding standards and training materials for engineering teams.
- Serve as the product security expert during incident response, from investigation to postmortem.
- Partner with GRC to produce evidence for audits and customer security reviews without compromising the security roadmap.
Requirements
- Prefer building systems that find all bug instances over fixing them individually.
- Proficient in using AI as part of the work process, with informed opinions on its utility and build vs. buy decisions for tooling.
- Ability to set architecture and standards across multiple codebases.
- Experience shipping production code and authoring fixes.
- Expert knowledge of web and API security.
- Expert knowledge of identity and access design (authentication, authorization, RBAC/ABAC).
- Expert knowledge of applied cryptography.
- Experience securing applications in cloud environments.
- Experience securing containerized workloads.
- Proven track record of driving security initiatives to completion within engineering organizations outside of direct reporting lines.
Skills
- Application Security
- Product Security
- Threat Modeling
- Security Architecture Review
- Authentication
- Authorization
- Encryption
- Tenant Isolation
- Secure Code Review
- Penetration Testing Management
- AI Security Assessment
- Vulnerability Management
- SAST
- DAST
- SCA
- Secrets Scanning
- CI/CD Integration
- Automation
- Incident Response
- GRC Partnership
- Web Security
- API Security
- Identity and Access Management
- Cryptography
- Cloud Security
- Container Security
Location
- Beacon HQ
- Portfolio company locations
Work Type
- Full-time
- Hybrid
Experience Level
- Senior
About the Company
- Beacon Software is building a generational software company.
- Values: Humility, Honesty, Hunger, Horizon.
- Focuses on truth-seeking, strong relationships, high standards, and long-term growth.
Equal Opportunity
- Beacon Software uses Artificial Intelligence and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications that match the key requirements for each role.
- AI does not make hiring decisions: Every application is reviewed by a member of our team, and all decisions throughout the process are made by humans.
- AI is used to support efficiency and consistency, not to replace human judgment.
- Committed to a fair, thoughtful, and equitable experience for every candidate.
