Jobs and Careers
GR

Security Engineer II- Application Security

Grubhub
United Statesfull_timeVerifiedPosted 20 Dec 2024
💰 $186,000/yr($124,000/yr – $186,000/yr)

About the role

About The Opportunity
We’re all about connecting hungry diners with our network of over 300,000 restaurants nationwide. Innovative technology, user-friendly platforms and streamlined delivery capabilities set us apart and make us an industry leader in the world of online food ordering. When you join our team, you become part of a community that works together to innovate, solve problems, grow, work hard and have a ton of fun in the process!

 

Why Work For Us

Grubhub is a place where authentically fun culture meets innovation and teamwork. We believe in empowering people and opening doors for new opportunities. If you’re looking for a place that values strong relationships, embraces diverse ideas–all while having fun together–Grubhub is the place for you!

Grubhub Security is charged to deliver tailored solutions which provides a safe and trustworthy experience for our users and more than 31.5 million customers. We are committed to maintaining the highest standards of security and compliance in all aspects of our operations. We pride ourselves on innovation, integrity, and a dedication to safeguarding our digital assets.

More About The Role:

Grubhub's Product Security team is seeking a talented Application Security Engineer to join our team. This role focuses on designing, integrating, and managing application security capabilities, analyzing findings, and ensuring security throughout the development lifecycle. Additionally, you will contribute to proactive security practices, such as threat modeling and secure architecture reviews. As an Application Security Engineer, you will leverage your engineering expertise to develop scalable, reusable solutions for integrating security capabilities, such as Static Code Analysis (SAST) and Software Composition Analysis (SCA) into CI/CD pipelines and developer workflows. These capabilities will seamlessly align with a centralized solution designed to manage scanning policies and process scanner outputs to feed it into our Vulnerability Management framework. The reusable tools and solutions you build will empower service and platform teams to independently integrate these capabilities into their pipelines, ensuring consistent security standards and actionable insights. Your work will play a critical role in elevating the security posture of Grubhub's services.

The Impact You Will Make:

  • Ensure that Grubhub’s key business initiatives are delivered securely.

  • Enable Grubhub to reduce its security risk and improve in security maturity Build highly scalable & reliable process to ensure and improve the efficiency, accuracy of the application security controls.

  • Deliver, deploy, maintain, and monitor the performance of application security controls, directly contributing to service readiness and resilience against evolving cyber threats.

  • Evaluate tools, technologies, frameworks, and vendors to improve Grubhub's product security posture in collaboration with senior Cybersecurity team members and partners from other teams.

  • Enable self-service capabilities for service and platform teams, providing scalable, reusable tools that allow them to integrate security into their workflows.

  • Promote a collaborative work culture and actively engage with domain experts across teams.

  • Develop and integrate application security capabilities (e.g., SAST, SCA) into CI/CD pipelines and developer environments.

  • Build reusable tools and containerized/CLI-based implementations for service and platform teams.

  • Help to design centralized solutions for managing scanning policies and processing tool outputs to ensure consistency and scalability.

  • Analyze security findings, prioritize vulnerabilities, and provide actionable recommendations to development teams.

  • Integrate analyzed code vulnerability into Grubhub’s vulnerability management service.

  • Partner with developers to enhance secure coding practices and streamline vulnerability remediation.

  • Conduct threat modeling sessions and architecture design reviews to proactively identify and mitigate risks.

  • Assess and refine application security tools and processes to ensure alignment with evolving engineering workflows and security needs.

What You Bring To The Table:

  • Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience).

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Grubhub

View company profile →