Ibotta

Security Engineer

Ibotta$115K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in security engineering, application development, or application security.
  • Proficiency in languages like Python, Go, or Java; experience with Docker/Kubernetes.
  • Strong knowledge of AWS security services and Infrastructure as Code (IaC) tools like Terraform.
  • Strong understanding of web API security patterns and modern authentication protocols.
  • Familiarity with OWASP Top 10 and experience with web application testing tools.
  • Effective communication skills for collaboration across technical and non-technical teams.
  • Experience building custom security tooling or automation scripts.

Responsibilities

  • Perform application security assessments, including code reviews and penetration testing.
  • Mature the bug bounty program to accommodate AI submissions and attack surface.
  • Analyze application architecture to identify weaknesses and areas for improvement.
  • Integrate and manage SAST, DAST, and SCA tools within the CI/CD pipeline.
  • Lead threat modeling for new application features with cross-functional stakeholders.
  • Develop secure coding practices and provide developer training.
  • Design, implement, and monitor security controls for cloud platforms (AWS/GCP).
  • Automate infrastructure security checks using IaC scanning tools.
  • Evaluate AI-generated code security and implement guardrails for model-serving endpoints.
  • Participate in a 24/7 on-call rotation and incident response.

Benefits

  • Flexible time off and a robust benefits package (medical, dental, vision)
  • Employee Stock Purchase Program and 401k match
  • Denver office perks including paid parking, snacks, and occasional meals
  • Relocation bonus for out-of-state candidates moving to Denver
Full Job Description
Security Engineer with a deep expertise in Application Security, Vulnerability Management, and Cloud Infrastructure to join our innovative team and contribute to our mission to Make Every Purchase Rewarding. In this role, you will be ensuring the security of our software development lifecycle (SDLC) and our cloud-native environments. A key focus of this position will be addressing the emerging security challenges posed by Artificial Intelligence (AI) technologies, specifically around secure AI coding practices and the infrastructure that supports AI/ML workloads.

This position is located in Denver, Colorado as a hybrid position requiring 3 days in office (Tuesday, Wednesday, and Thursday). Candidates must live in the United States.

Not based in Denver? We will offer a relocation bonus to help make your move to the Mile High City a smooth one.

What you will be doing:
  • Perform application security assessments, including manual code reviews and penetration testing.
  • Mature Ibotta's bug bounty program to scale with AI generated submissions and attack surface.
  • Analyze Ibotta's application architecture to identify weaknesses and develop opportunities for improvement.
  • Integrate and manage SAST, DAST, and SCA tools within the CI/CD pipeline.
  • Lead threat modeling for new application features with key stakeholders across mobile, platform, infrastructure and AI enablement.
  • Develop and maintain secure coding practices, provide training to developers.
  • Work with Ibotta's engineering team to design, implement, and monitor runtime and container security controls across cloud platforms (AWS/GCP).
  • Automate infrastructure security checks using Infrastructure as Code (IaC) scanning tools.
  • Evaluate the security of AI-generated code and implement guardrails for model-serving endpoints in the development process.
  • Stay ahead of the curve on AI-specific threats such as prompt injection, data poisoning, and model inversion.
  • Participate in a 24/7 on-call rotation and incident response.
  • Embrace and uphold Ibotta's Core Values: Integrity, Boldness, Ownership, Teamwork, Transparency & A Good Idea Can Come from Anywhere


What we are looking for:
  • 4+ years in security engineering, application development, or application security.
  • Proficiency in languages like Python, Go, or Java; experience with Docker/Kubernetes.
  • Basic knowledge of networking security is a plus.
  • Strong knowledge of AWS security services and IaC (Terraform). Experience writing secure IAM policies and other configurations in Terraform a plus.
  • Understanding of Continuous Integrations/Testing/Delivery
  • Strong understanding of Web API security patterns and modern authentication protocols.
  • Familiarity with OWASP Top 10 and implementing technical controls to address vulnerabilities.
  • Working knowledge of web application testing tools.
  • One or some combination of the following are a plus but not required: CompTIA SecAI+, eCPPT, eWPT, GWAPT, OSCP, or similar.
  • Must have the ability to work effectively across the organization/collaborate effectively with both technical and non-technical team members, possess excellent oral & written communications skills, and demonstrate effective problem-solving skills.
  • Experience building custom security tooling or automation scripts.


Additional Details:
  • This position is located in Denver, CO and includes competitive pay, flexible time off, benefits package (including medical, dental, vision), Employee Stock Purchase Program, and 401k match. Denver office perks include paid parking, snacks, and occasional meals.
  • Base compensation range: $115,000 - $130,000. Equity is included in overall compensation package. This compensation range is specific to the United States labor market and may be adjusted based on actual experience.
  • Applicants must be currently authorized to work in the United States on a full-time basis.
  • Applicants are accepted until the position is filled.
  • For the security of our employees and the business, all employees are responsible for the secure handling of data in accordance with our security policies, identifying and reporting phishing attempts, as well as reporting security incidents to the proper channels.


Recruiting Agency Notice
Ibotta does not accept agency resumes and is not responsible for any fees related to unsolicited resumes. Please do not forward resumes to any Ibotta employees.

#LI-Hybrid

#BI-Hybrid

About Ibotta

Ibotta is a mobile app that allows users to earn cash back on purchases made at participating retailers. The app was founded in 2011 and has since grown to become one of the most popular shopping apps in the United States. Ibotta partners with over 1,500 retailers, including Walmart, Target, and Amazon, to offer users cash back on their purchases. The company has raised over $85 million in funding and has been recognized as one of the fastest-growing companies in the country by Inc. Magazine.
Learn more about Ibotta
Size
500 employees
Industry
Founded
2011

Similar Jobs

More Jobs at Ibotta

More Information Technology Jobs

Find similar Security Engineer jobs: