Security Engineer
fabricAbout the role
Who we are: We are a brilliant team making our own history to evolve the ecommerce industry. Our mission is to accelerate the gross merchandise value of the internet by ending the pain of replatforming. Our products are centered around optimizing the digital commerce experience so everyone has the opportunity to shop seamlessly. We provide them with the last platform they will ever need.
Your next career move should be bold and we have the experience you are seeking. We build and ship products & solutions that enable merchants to compete and deliver a world class differentiated shopping experience online.
Are you a disruptor? We want your ideas, skills, and expertise to help build our products that will make customers happier when they shop online and we want to build these tools in such a way that any merchant can deploy these experiences painlessly and quickly, The best part? Every bit of your work at fabric will help scale the business of our customers.
No matter what field you are in, fabric has exciting opportunities for people who are passionate about making a difference and skilled at what they do!
Here are four questions you should ask yourself:- Do I believe in fabric's mission?- Am I eager to build cool things?- Am I excited to collaborate with brilliant people?- Am I motivated to disrupt e-commerce?
If the answer is yes, we want to talk to you!
Where we hire:This role can be located in California, Washington State, Massachusetts, Texas or New York.
Your next career:The successful candidate will have prior experience in application security in the retail/ecommerce industry and is a hands-on technologist. This person is comfortable with multiple priorities in a fast-paced environment and is responsible for the ownership of key projects within the security space. You will also be responsible for driving for secure code design and integration of our software stack to keep our customers’ data safe while focusing on mitigating attack risks, securing cloud transformation, and fostering a culture of security and reliability within the company.
Your responsibilities:- Ability to work independently and as part of a team.- Experience in threat modeling methodologies (e.g. STRIDE, DREAD) and tools to develop and maintain threat models that reflect the organization's security posture.- Experience working with developers to communicate deficiencies and implement security measures.- Design, deploy, and maintain centralized security tools, technologies, and controls to monitor and protect our infrastructure and applications.- Help build and maintain runbooks and document policies and procedures.- Develop and maintain security metrics to track progress toward security goals.- Maintain essential skills in modern technology. Use automation wherever possible.- Conduct security reviews for new and existing software systems, integrations, and operational processes, which includes security testing and vulnerability scanning.- Review and enhance access controls, authentication mechanisms, and data encryption methods.- Collaborate with IT, development, and operations teams to integrate security best practices into our systems and software development lifecycle.- Build and manage services, tools, and integrations that will automate security controls within CI/CD pipelines.- Assess, identify, and monitor security risks, vulnerabilities, and threats, and develop effective mitigation strategies with engineering stakeholders to ensure timely remediations.- Educate and train employees on security awareness and best practices.- Assist systems integration with fabric customers to ensure security best practices- Provide guidance and mentorship to junior team members.- Participate in security detection, incident response, and post-response activities.- Stay up-to-date with industry trends, emerging threats, and security standards to adapt and improve our security posture.- Support and drive compliance programs with relevant regulations and industry standards (e.g., PCI DSS, SOC2, NIST).
What you bring to the table: - 5+ years of prior experience in security engineering/applications security- 2+ years of experience with AWS - Experience with scripting languages such as Python or JavaScript.- Experience working with OWASP and NIST security standards and frameworks. - Experience within DevSecOps, CI/CD processes, SDLC, and related tools such as Jira, Jenkins, Artifactory, Bitbucket, GitHub, GitLab, etc.- Ability to establish and report metrics and KPIs to the executive leadership team to measure the effectiveness of Security Engineering
Preferred: - Previous experience as a DevOps/DevSecOps Engineer supporting applications and platforms running in private or public cloud (such as Rancher, Anthos, AWS, GCP, VMWare)- Experience with SIEM tools. Prefer experience with tools such as Splunk or Datadog.- Proven experience in information security, with a focus on ecommerce or web applicatio
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s