As PandaDoc continues to scale, we’re expanding our security team and looking for an Application Security Engineer to help shape and strengthen our security foundations. In this role, you’ll take ownership of key security initiatives across our application, working closely with engineering to embed security into every stage of development. You’ll contribute to building a proactive, automation-driven security culture while addressing both current risks and emerging challenges, including AI security.
In this role, you will:
Monitor and test information systems to identify vulnerabilitiesExecute or manage the remediation of identified vulnerabilitiesRespond to security incidents and perform root cause analysisAssess and understand PandaDoc’s current security framework and future architecture, providing recommendations for risk reductionDesign, implement, maintain, and evangelize automated security solutionsWork closely with engineering teams to implement new security controlsAnalyze and monitor relevant security threats and prevention measures based on industry trends and standardsPerform cloud services hardening, including reviewing roles and permissions for services and APIsHelp address emergent threats in AI security as PandaDoc deploys AI in its product and for internal useOur stack:
Service-oriented architectureTwo main stacks: Java and PythonAmazon Web Services: EKS, RDS, ElastiCache, etc.A combination of AWS native and 3rd party security tools for infrastructure and application security (WAF, CNAPP, SCA/SAST, DAST, AWS GuardDuty, etc.)About you:
2+ years of cloud security experience implementing security controls and best practices in AWS, GCP, or Microsoft Azure2+ years of experience with security management tools, including IPS/IDS, WAF, vulnerability scanning, and penetration testingGood understanding of Access Control and Identity Access Management principles (SAML 2.0, OAuth, JWT, etc) Experience with implementing DevSecOps practices in SSDLCSolid interpersonal, written, and verbal communication skillsUpper-Intermediate English level (B2+)Company Overview:
PandaDoc empowers more than 60,000 growing organizations to thrive by taking the work out of document workflow. PandaDoc provides an all-in-one document workflow automation platform that helps fast scaling teams accelerate the ability to create, manage, and sign digital documents including proposals, quotes, contracts, and more.