Blackline
BlackLine automates and controls financial close processes for midsize and large organizations.
Remote
Hybrid

Senior Application Security Engineer

Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Employer Provided Salary: 145,000-223,400 Annually
Salary data is provided by the employer. Please note this is not a guarantee of compensation.

Get to Know Us:
It's fun to work in a company where people truly believe in what they're doing!
Since being founded in 2001, BlackLine has become a leading provider of cloud software that automates and controls the entire financial close process. Our vision is to modernize the finance and accounting function to enable greater operational effectiveness and agility, and we are committed to delivering innovative solutions and services to empower accounting and finance leaders around the world to achieve Modern Finance.
Being a best-in-class SaaS Company, we understand that bringing in new ideas and innovative technology is mission critical. At BlackLine we are always working with new, cutting edge technology that encourages our teams to learn something new and expand their creativity and technical skillset that will accelerate their careers.
Work, Play and Grow at BlackLine!
Make Your Mark:
At BlackLine, we're committed to bringing passion and customer focus to the business of enterprise applications. BlackLine is looking for a creative, polished Senior Application Security Engineer to join our team.
You'll Get To:

  • Perform static analysis security reviews using automated tools like Veracode and manual source code review
  • Conduct software composition analysis to identify security risks associated with third-party software and effectively prioritize risks
  • Identify security risks and areas of exposure in applications developed and/or used by BlackLine
  • Collaborate with software development team in remediating the identified security vulnerability and ensure defense mechanisms are implemented of highest standards
  • Review technical specification documents, perform threat modelling to determine risks, define application security requirements, and develop consistent threat modelling artifacts
  • Oversee development of security components throughout all the stages of the Software Development Lifecycle
  • Perform Dynamic security assessments or manual penetration testing of BlackLine applications
  • Monitor industry trends and threat landscape and recommend necessary controls or countermeasures
  • Recommend and lead projects to improve the application security risk management posture of Blackline at large
  • Lead Security Champions program to train developers on secure coding techniques and security best practices
  • Mentor team of application security engineers and provide technical guidance
  • Participate in development of security policies, standards, and processes
  • Participate in incident handling and perform application-related forensic activitie
  • Perform other duties as assigned
  • Provide limited supervision to others through motivation, direction, review and feedback of assigned tasks
  • Working Conditions: This role will be expected to be online during business hours for most of our customers (North America) and to have coverage for business operations conducted during business hours in other HQ (e.g., EU issues that are Resolve Immediately)
  • Application Security office hours are 0800-1700, with overnight incident coverage provided by on call for Security Operations.


What You'll Bring:

  • 5+ years of hands-on application security experience, strong emphasis on prior development experience.
  • Advanced knowledge of OWASP Top 10 risks and CWE TOP 25 (e.g. Broken Access Control, SSRF, Injection, cookie/header/encoding manipulation, Cryptographic failures, Broken Authentication, Insecure Design etc).
  • Advanced knowledge of web application technologies, MVC, Ajax, XML, JSON, SOA, SSL, web-related protocols and services.
  • Intermediate knowledge of MS SQL. Basic knowledge of other commonly used DBMS.
  • Ability to identify security vulnerabilities from static, dynamic and interactive testing tools and techniques.
  • Knowledge of encryption technologies, secure communications using TLS, and secure credentials management.
  • Intimate familiarity with web application testing tools (eg: Burp, Fiddler, Veracode, Snyk, Whitehat DAST). Ability to write proof-of-concept exploits is a big plus.
  • Ability to define application security requirements and build secure web application solutions.
  • Advanced written and verbal communication skills including ability to present technical subjects to non-technical audiences.
  • Strong work ethic, attention to detail, and organizational skills.
  • Ability to collaborate in a team and work independently.
  • Conceptual understanding of software development principles and SDLC models, Agile experience is a plus.
  • Intermediate proficiency with the Microsoft Office suite.


We're Even More Excited If You Have:

  • Advanced experience with at least one scripting language (e.g.: Perl, Python)
  • Strong experience with devops in public cloud and "big data" storage, databases, and APIs such as BigQuery, vSQL, etc.
  • Hands-on development experience and thorough understanding of object-oriented programming, preferably Java, C#, ASP.NET
  • Security Certifications GWEB, OSCP, Burp Certified Practitioner is a plus


Thrive at BlackLine Because You Are Joining:

  • A technology-based company with a sense of adventure and a vision for the future. Every door at BlackLine is open. Just bring your brains, your problem-solving skills, and be part of a winning team at the world's most trusted name in Finance Automation!
  • A culture that is kind, open, and accepting. It's a place where people can embrace what makes them unique, and the mix of cultural backgrounds and varying interests cultivates diverse thought and perspectives.
  • A culture where BlackLiner's continued growth and learning is empowered. BlackLine offers a wide variety of professional development seminars and inclusive affinity groups to celebrate and support our diversity.


BlackLine is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, race, age, religious creed, national origin, physical or mental disability, ancestry, color, marital status, sexual orientation, military or veteran status, status as a victim of domestic violence, sexual assault or stalking, medical condition, genetic information, or any other protected class or category recognized by applicable equal employment opportunity or other similar laws.
BlackLine recognizes that the ways we work and the workplace itself has shifted. We innovate in a workplace that optimizes a combination of virtual and in-person interactions to maximize collaboration and nurture our culture. Candidates who live within a reasonable commute to one of our offices will work in the office at least 2 days a week.
Salary Range:
USD $145,000.00 - USD $193,000.00
Pay Transparency Statement:
Placement within this range depends upon several factors, including the applicant's prior relevant job experience, skill set, and geographic location. In addition to base pay, BlackLine also offers short-term and long-term incentive programs, based on eligibility, along with a robust offering of benefit and wellness plans.

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are Blackline Perks + Benefits

Blackline Benefits Overview

Healthy employees are happier and more engaged. At BlackLine, medical, dental, and vision coverage is taken care of by the company, along with unlimited paid time off and other perks to help you take care of your mental and physical health and wellness.

Your financial wellness matters too. we offer a 401(k) plan with matching, competitive compensation, and an employee stock purchase plan to ensure you keep current with your value in the marketplace and plan for your future. We also offer extensive career and personal development with a wide range of learning opportunities.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Employee resource groups
Employee-led culture committees
Flexible work schedule
Remote work program
Diversity
Documented equal pay policy
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
At BlackLine, we feel that paying 100% of our employees’ health benefits is 100% the right thing to do. Medical, dental, and vision are taken care of by the company.
Life insurance
Pet insurance
Wellness programs
Team workouts
BlackLine has been offering company wide virtual fitness classes such as, Aerobics and Yoga!
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
BlackLine has been offering company wide virtual fitness classes such as, Aerobics and Yoga!
Company equity
Employee stock purchase plan
BlackLine offers and Employee Stock Purchase Plan with the ability to buy stock at a discounted price.
Performance bonus
Charitable contribution matching
Child Care & Parental Leave
Childcare benefits
Generous parental leave
Family medical leave
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid holidays
Paid sick days
Flexible time off
Floating holidays
Office Perks
Commuter benefits
Company-sponsored outings
BlackLine hosts company outings several times per year.
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
We offer employees free on-site garage parking.
Fitness stipend
Home-office stipend for remote employees
Professional Development
Job training & conferences
Tuition reimbursement
Lunch and learns
Promote from within
Continuing education available during work hours
Online course subscriptions available
Customized development tracks

Additional Perks + Benefits

We’re better together and know that amazing individuals make amazing teams. We also know that we bond through socializing and shared experiences. That’s how teams gel and support each other.

So, we like to play games together: table tennis, poker, and video games. We encourage company sports leagues and fitness groups. We relax with happy hours and team get-togethers, and we never let a holiday season go by without a celebration.

More Jobs at Blackline

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about BlacklineFind similar jobs like this