EasyPost
Application Security Engineer
About this role
EasyPost, a YC-backed unicorn, seeks an Application Security Engineer III to lead security architecture and strategy across the company's shipping platform. You'll design scalable defense systems, embed security throughout the development lifecycle, and champion DevSecOps practices while enabling teams to build secure code at scale.
What you'll do
- Design and maintain scalable security systems and infrastructure aligned with business objectives
- Integrate security and privacy controls into product development from inception through delivery
- Build automated systems and programs to scale security operations efficiently
- Champion shift-left methodologies and DevSecOps adoption across CI/CD pipelines
- Architect customer-facing security features and maintain high-fidelity alerting infrastructure
- Create documentation, training materials, and self-service resources to empower developers
What they're looking for
- Proficiency in Python, Ruby, Go, or Rust
- Large-scale web application and API security design
- Security design reviews and vulnerability assessments
- Threat modeling and risk management communication
- Compliance frameworks (SOC2, ISO 27001, HIPAA, GDPR, CCPA)
- Cloud migration experience (AWS, GCP, Azure)
- Mixed computing environment administration
- Vendor risk assessment and management
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
EasyPost
EasyPost builds a shipping platform that helps businesses manage logistics and delivery operations. The company is hiring for security and engineering roles, including senior security architects who design defense systems and drive secure development practices across the platform.
View all jobs at EasyPostLikely interview questions
- Walk us through your experience designing and implementing security architecture for large-scale web applications or APIs. How did you approach threat modeling and what frameworks did you use?
- Describe a time you championed a 'shift-left' security initiative or DevSecOps adoption. What tools and processes did you implement, and what was the impact on development velocity?