remote
Application Security Engineer - Intercom
Security Engineer
Lead the design and implementation of secure software practices, performing threat modeling, code reviews, and penetration tests to protect AI‑driven customer support platforms using AWS and modern CI/CD pipelines.
About the role
Key Responsibilities
- Conduct threat modeling and risk assessments for new and existing AI customer support features.
- Perform secure code reviews and penetration tests to identify and remediate vulnerabilities.
- Integrate security controls into CI/CD pipelines, ensuring automated scanning and compliance checks.
- Collaborate with product, engineering, and DevOps teams to embed security best practices into the development lifecycle.
- Maintain up‑to‑date knowledge of OWASP Top 10, cloud security, and emerging attack vectors.
Requirements
- 3+ years of experience in application security, preferably in SaaS or AI‑driven platforms.
- Hands‑on expertise with OWASP guidelines, static/dynamic analysis tools, and penetration testing frameworks.
- Strong understanding of AWS security services (IAM, KMS, Secrets Manager) and CI/CD security automation.
- Excellent communication skills to translate technical findings into actionable recommendations.
- Proactive mindset with a passion for staying current on security trends and emerging threats.
Skills
owasppenetration testingaws