Back to Jobs
Development Just now

Security Engineer / Analyst

United StatesUnited States
Full-time
$109,000 - $144,000
Mid-Level

Job Description

Key Skills Required

Master these to land this role

BackendBestseller 🔥
Learn in 18 Hours
DevOpsBestseller 🔥
Learn in 63 Hours
Cloud SecurityCybersecurityClojure

Want to know if you're a match for this job?

Calculate My Match Score

About Ladder

We saw a problem within the life insurance industry: getting covered took too long, involved too much paperwork, and required too many in-person meetings with sales agents. Having lost his father at a young age, our CEO, Jamie, was determined to make it easier for people to get the coverage they needed to provide for their families. So, we got to work. We developed a method of real-time underwriting leveraging AI and, in doing so, reduced the months-long process of applying for life insurance to minutes. Our digital experience is quick (instant decisions!), loved by users (check out our Trustpilot or Google reviews) and prolific ($74 billion+ in coverage provided).

About the Role

We are looking for a cybersecurity unicorn. A Security Engineer / Analyst who brings a rare blend of application security engineering and risk management maturity. In this role, you will be the driving force behind our vulnerability management lifecycle, balancing day-to-day security operations with development-facing vulnerability management and compliance.

Your primary mission will be embedded within our development lifecycles, taking ownership of application security vulnerability management for our engineering teams. Because our backend infrastructure runs heavily on Clojure, you won't just be running automated scanners, you will actively look at code and leverage your functional programming experience to strengthen our shift-left security philosophy. Beyond AppSec, you will wear multiple hats: monitoring our cloud infrastructure and responding to alerts, conducting security risk reviews, supporting compliance audits, and ensuring our day-to-day workspace remains locked down.

The ideal candidate is well-rounded and has the ability to interact with all levels of management and external auditors, and operate effectively in a rapidly scaling, dynamic environment. We are looking for someone who is organized, self-motivated, has excellent problem-solving and writing skills, and enjoys working with people in a challenging and fast-paced environment.

What You’ll Do

  • Partner directly with development teams to champion application security vulnerability management. You will triage vulnerabilities within a high-scale Clojure ecosystem and assist with remediation code fixes.
  • Configure, fine-tune, and monitor our cloud security posture leveraging Security Operations tools (SIEM, SOAR, CSP, CNAPP) to detect and respond to threats in real time.
  • Conduct thorough Security Reviews and risk assessments on internal architecture, third-party vendors, and APIs to ensure alignment with our corporate risk tolerance and compliance standards.
  • Maintain and optimize our day-to-day corporate workspace security, ensuring identity access management, device compliance, and productivity tools are highly secure yet frictionless for the team.
  • Act as a security advocate across teams. Mentor engineers on secure coding practices, establish secure defaults, and make practical risk decisions that scale with our growth.

Experience Required

  • 4+ years of software engineering and/or cybersecurity experience, backed by a strong foundation in Computer Science, Cyber Security, or a related field.
  • Hands-on experience coding in Clojure and working within the JVM environment. You are comfortable reading functional code, understanding immutable data structures, and collaborating directly with backend engineers on code-level fixes.
  • Hands-on experience securing modern cloud infrastructures, as well as experience working incident response.
  • Thrive in dynamic environments. You don't just clear alerts; you look for the root cause of issues to design security frameworks that prevent entire classes of vulnerabilities from happening in the first place.
  • Hold baseline certifications such as CompTIA Security+ or equivalents. Having an advanced credential like the CISSP is highly preferred and considered a major plus.

Technologies Used

  • Backend & Code: Clojure, JVM, TypeScript, JavaScript
  • Cloud & Infrastructure: GCP, Kubernetes, Docker, Terraform, GraphQL
  • Security & Data Operations: Google Security Command Center, Chronicle, Datomic, BigQuery, Kafka

What we Offer

  • Excellent medical, dental, and vision coverage | We offer competitive healthcare, dental and vision plans for you and your family.
  • Flexible paid time off | Take the time that you need to rest and recharge, including our week-long winter holiday closure.
  • Stock options | We offer competitive stock option packages to participate in the success of building Ladder.
  • A rewarding 401k match program | We'll match up to 4% of your contributions as you save for your retirement goals.
  • Ladder Fit Program | Your health matters. That's why Ladder provides a monthly stipend for wellness-related expenses.
  • Paid parental leave | We think it's crucial that new parents have time to adjust to their new lives without worrying about work, so we provide all parents inclusive of birthing, adoption, or fostering ten weeks of paid baby bonding.
  • Work-from-home flexibility and support | We recognize that everyone's homelife is different and support remote work. Upon joining, we provide a one-time remote office stipend for all team members and then a monthly stipend to cover WFH costs such as the internet.
  • Fun company-wide events | We genuinely enjoy spending time together. That's why we plan fun virtual events to let loose and laugh.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More