Hopper

Senior Security Engineer- USA

Hopper$120K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • At least 5 years experience in software and/or platform engineering.
  • Deep experience in application security and vulnerability management.
  • Hands-on experience with cloud infrastructure, ideally GCP/GKE or equivalent.
  • Demonstrated habit of using AI tools as a core part of work.
  • Bias toward automation; instinctively write tools instead of runbooks.
  • Comfort with ambiguity and ownership in problem-solving.
  • Experience influencing engineering culture around security.

Responsibilities

  • Own and evolve the vulnerability management program focused on application security.
  • Build and maintain security tooling integrated into CI/CD pipelines.
  • Use AI to automate analyses and build intelligent tooling.
  • Assess and improve telemetry across systems.
  • Work with engineering teams to influence secure development practices.
  • Investigate and respond to security findings as needed.
  • Adapt quickly as priorities shift within an agile environment.

Benefits

  • Unlimited PTO for work-life balance.
  • Carrot Cash travel stipend for expenses.
  • Access to co-working space on demand through FlexDesk.
  • Work-from-home stipend to support remote work.
  • Generous parental leave above industry standards.
  • Small, dynamic teams enabling significant impact.
  • Open communication with management and company leadership.
  • 100% employer paid medical, dental, and vision insurance.
  • Access to disability and life insurance coverage.
  • Health Reimbursement Account (HRA) availability.
Full Job Description
About the Role

Hopper's Security team is small by design and consequential by impact- and this role sits at the centre of it. As a Senior Security Engineer, you'll own the tooling, automation, and processes that keep our applications secure across their entire lifecycle, building the systems that make security invisible to developers and unavoidable by default. This is a builder's role in every sense: you'll write code, ship tools, and use AI as a core part of how you work - not as a novelty, but as a force multiplier.

What would your day-to-day look like
  • Own and evolve our vulnerability management program with a focus on application security - container images, dependencies, code scanning, and runtime detection
  • Build and maintain security tooling that integrates directly into CI/CD pipelines and developer workflows, so security happens automatically rather than as a gate
  • Use AI extensively to write code faster, automate analyses that would otherwise require manual review, and build intelligent tooling that scales beyond what a small team could achieve manually
  • Assess and improve how we leverage available telemetry across our systems
  • Work directly with engineering teams to influence secure development practices - not by writing standards and documents, but by shipping tools and defaults that make the secure path the easy path
  • Investigate and respond to security findings when needed, but spend more of your time building systems that prevent and detect issues than manually chasing them
  • Adapt quickly as priorities shift - our team is agile and tomorrow's challenge may look different from todays

An ideal candidate has
  • At least 5 years experience software and/or platform engineering, with the ability to design, build, and maintain production-quality tools
  • Deep experience in application security and vulnerability management - you understand CVEs, dependency risks, container security, and SDLC integration, and you have opinions about what's worth fixing and what's noise
  • Hands-on experience with cloud infrastructure, ideally GCP/GKE or equivalent, with the ability to adapt to our stack
  • A demonstrated habit of using AI tools - coding assistants, LLMs - as a core part of how you build and analyse, not an occasional shortcut
  • A bias toward automation - when you see a repetitive manual task, your instinct is to write a tool, not a runbook
  • Comfort with ambiguity and ownership - you'll often be the only person on a problem and will need to make judgment calls on priority, approach, and scope without waiting for direction
  • Experience influencing engineering culture around security, knowing how to make developers care without slowing them down
  • Strong written and verbal communication skills, including the ability to articulate our security posture clearly to customers when needed


Perks and benefits of working with us
  • Well-funded and proven startup with large ambitions, competitive salary and the upsides of pre-IPO equity packages.
  • Unlimited PTO.
  • Carrot Cash travel stipend.
  • Access to co-working space on demand through FlexDesk AND Work-from-home stipend.
  • Please ask us about our very generous parental leave, much above industry standards!.
  • Entrepreneurial culture where pushing limits and taking risks is everyday business.
  • Open communication with management and company leadership.
  • Small, dynamic teams = massive impact.
  • 100% employer paid Medical, Dental and Vision coverage for employees.
  • Access to Disability & Life insurance.
  • Health Reimbursement Account (HRA).
  • DCA/ FSA and access to 401k plan.


#LI-REMOTE

About Hopper

Hopper is a travel booking app that uses big data to predict and analyze airfare and accommodations. The app provides personalized recommendations and alerts users when prices are expected to rise or fall. Hopper was founded in 2007 and is headquartered in Montreal, Canada. The company has raised over $400 million in funding and has been recognized as one of the most innovative companies in travel.
Learn more about Hopper
Size
1,000 employees
Industry
Founded
2007

Similar Jobs

More Jobs at Hopper

More Information Technology Jobs

Find similar Senior Security Engineer- USA jobs: