5-7 years of experience in application security and product/platform securing
Proficiency in OWASP Top 10, threat modeling, and code reviews
Experienced with AI tooling in daily operations
Solid understanding of infrastructure security in AWS
Familiarity with Python and TypeScript programming languages
Knowledge of SOC processes and incident response
Understanding of compliance frameworks like SOC 2 and ISO 27001
Responsibilities
Review code, architecture, and designs pre-release for security vulnerabilities
Guide engineering features and designs toward security best practices
Conduct hands-on manual pentesting for relevant code changes
Build and maintain security tools to ensure scalability
Advise DevOps teams on security best practices for infrastructure
Engage with clients to address security queries and needs
Coordinate with multiple domains to integrate security across the organization
Benefits
Ownership of significant projects influencing company outcomes
Gain exposure working with the executive team and strategic decision-making
Direct influence on product direction through real-time feedback
Opportunity to work with cutting-edge AI technologies
Establish reputation as a leader in AI implementation across industries
Meaningful equity in a fast-scaling venture-backed company
A supportive culture for top talent focused on growth and achievement
Comprehensive health coverage available from day one
Generous PTO and supportive work-from-home benefits
Full Job Description
The Role
We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune 500 customers. In this pivotal role, you will be working in close partnership with our engineering teams, ensuring that everything they build holds up to our security standards. While your primary focus will be application security, you are joining a small, elite team, and as such you will also work cross-domain, including working with MDM, or talking with customers directly.
What You'll Do
Stay ahead of engineering: review code, architecture, design, anything that's being considered for release
Guide features and designs toward security
Provide hands-on manual pentesting on relevant code changes
Build and maintain security tooling to ensure security scales with organisation
Advise the DevOps team on infrastructure security best practices
Help out with client-facing security needs, such as client calls
What We're Looking For
Proven experience securing products & platforms, collaborating with development teams
Strong expertise in application security: OWASP Top 10, threat modeling, code reviews, architecture design
Proficiency with AI tooling, as part of your day-to-day activities
Solid understanding of AI itself, including AI threats, adversarial testing
Familiarity with AWS and infrastructure security overall
Be comfortable writing and reviewing Python and TypeScript, with other coding experience a plus
Experience with incident response and SOC processes
Knowledge of compliance frameworks: SOC 2, ISO 27001, NIST
Experience with enterprise security processes, such as security questionnaires and client calls
We don't expect candidates to have deep expertise in every area; strength in application security with curiosity and adaptability across adjacent domains is key
What You'll Get
Ownership & Rapid Growth
Outsized missions from day one, with direct responsibility for company-defining projects
Work alongside the executive team with transparency into strategy and decision-making
Influence on direction through real-time customer feedback and market insights
AI-First Operator
Work directly with cutting-edge AI models and next-generation platforms
Build expertise in enterprise AI implementation across Fortune 500 companies and multiple industries
Establish yourself as a recognized leader among peers in shaping how AI transforms work at a global scale
Compensation
Competitive salary including base + bonuses
Comprehensive health coverage (medical, dental, vision) from day one
Generous PTO, company-wide R&R shutdowns, and paid parental leave
Retirement plan support for US and global employees
A WFH stipend, phone stipend and support to work in a We Work or other space as preferred.
Equity
Meaningful ownership in a venture-backed company at a growth inflection point
Financial upside that comes from scaling fast
Top-up grants as we scale and you deliver exceptional performance - your compensation grows alongside your impact
Top-Performing Culture
A culture built for top talent: intensity to win, growth without limits, and a team that solves hard problems and celebrates big wins together
Location and Work Environment
We're looking for a candidate that can fully support our team in ET time zone (e.g. Toronto, NYC). While we're open to candidates from other areas, they need to be generally available during Eastern Time working hours. have valid travel documents without work authorization restrictions in the US.
#LI-HYBRID
About Valence
Valence is a specialty chemical company that produces a range of products used in the oil and gas industry. The company's products include drilling fluids, completion fluids, and production chemicals. Valence also provides custom chemical blending services. The company was founded in 2014 and is headquartered in Houston, Texas.