CookUnity Logo

CookUnity

Senior Application Security Engineer

Reposted 2 Days Ago
In-Office or Remote
Hiring Remotely in New York, NY
150K-180K Annually
Senior level
In-Office or Remote
Hiring Remotely in New York, NY
150K-180K Annually
Senior level
Lead application security efforts by performing assessments, code reviews, penetration testing, and promoting secure coding practices within the engineering teams.
The summary above was generated by AI
About CookUnity:

Food has lost its soul to modern convenience. And with it, it has lost the power to nourish, inspire, and connect us. So in 2018, CookUnity was founded as the first-of-its-kind platform that connects the world with the source of truly great food: chefs. Today, CookUnity delivers 50 million meals a year from the industry’s best chefs to homes all over the country. Fresh. Ready-to-eat. And crafted with the passion that nourishes body and soul.

Unwilling to stop there, CookUnity is expanding beyond delivery to become an ever-innovating marketplace focused on our singular mission: empower Chefs to nourish the world.

If that mission has you hungry in more ways than one, you’ve found the right job posting.


The Role:

Become a founding member of the Application Security team at CookUnity. You’ll work closely with disparate groups inside of CookUnity’s engineering organization, ranging from our Infrastrcuture and Software Engineering teams to ensure were free from high risk vulnerabilities but also building secure by design solutions.

Responsibilities:
  • Lead application security efforts by performing security assessments, code reviews, and penetration testing focused on applications developed in Kotlin, Java, and TypeScript.
  • Identify, classify, prioritize, and track remediation of vulnerabilities such as those listed in the OWASP Top 10 and other common weaknesses.
  • Use and maintain application security tools such as Burp Suite for dynamic testing, SAST/DAST/IAST tools, and other automated security scanners.
  • Collaborate closely with software development teams to enforce secure coding standards and hold Software Engineers accountable for patching vulnerabilities within defined SLAs.
  • Integrate security testing and automation into CI/CD pipelines to ensure continuous security validation.
  • Define and maintain security requirements and best practices aligned with industry standards such as OWASP, NIST, ISO, PCI DSS, and GDPR.
  • Conduct threat modeling, risk assessments, and security design reviews for new and existing applications.
  • Promote security awareness and provide training to development teams on secure coding and vulnerability mitigation.
  • Respond to security incidents and support remediation efforts.
  • Recommend and implement new security tools and technologies to improve application security posture.
  • Work in Agile and DevSecOps environments to embed security throughout the software development lifecycle.
Minimum Requirements:
  • Bachelor’s degree in Computer Science, Cybersecurity, or related field.
  • 6-8+ years of experience in application security, secure coding, and vulnerability assessment.
  • Strong development background with hands-on experience in Kotlin, Java, and Typescript.
  • Deep understanding of OWASP Top 10, CWE, and common web and API vulnerabilities.
  • Proficient with security testing tools such as Burp Suite, Fortify, Veracode, or similar.
  • Experience with secure SDLC, DevSecOps practices, and integrating security into CI/CD pipelines.
  • Familiarity with authentication and authorization protocols like OAuth2, OIDC, and SAML.
  • Ability to work effectively with development teams, guiding and holding them accountable for timely vulnerability remediation.
  • Relevant certifications such as CISSP, CSSLP, OSCP, GWAPT.
  • Fluency in English.
Preferred Requirements:
  • Knowledge of cloud security (AWS, GCP, Azure) and container security (Docker, Kubernetes) is a plus.

Benefits

🩺  Health Insurance coverage

🌅 401k Plan

📈 We grow, you grow: Stock Options Plan granted on Day 1

🌟 Eligible for a bi-annual performance bonus

⛱ Unlimited PTO

🗓️ 5- year Sabbatical: After 5 years with CookUnity, you get a 4-week paid sabbatical

🐣 Paid Family leave

🕯 Compassionate Leave: 3-5 days each time the need arises

🥘 A generous amount of CookUnity credits to enjoy our amazing meals, added to your account, monthly

🧘🏽‍♀️ Wellness perks: access to a nutritional coach and fitness subsidies to build a healthy lifestyle

👩🏾‍🏫 Personalized Spanish coach

🌟 Awesome opportunity to join a company that is looking to change how we eat and how chefs work!



CompensationAll final pay rates will be determined by candidates experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.
Pay Range for this position
$150,000$180,000 USD

If you’re interested in this role, please submit your application, and if we think you might be a fit, we'll get in touch with you. Thank you for your time!


CookUnity is an Equal Opportunity Employer. We are dedicated to creating a community of inclusion and an environment free from discrimination or harassment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, citizenship status, protected veteran status, genetic information, or physical or mental disability.

A quick note for all candidates
We’ve recently seen an increase in recruitment scams across the industry, and we want to make sure you (and your data) stay safe while applying to CookUnity. We also want you to know that we take this seriously — sometimes, as part of our process, we may ask for a brief “proof of humanity” to confirm that we’re connecting with a real person, not an impersonator. Here are a few tips to help you protect yourself and know what to expect from us:

  • Apply only through our official channels. All open roles are listed on our official careers page: careers.cookunity.com
  • Our recruiters are real people — and easy to verify. You can always find them on LinkedIn with verified profiles. If you’re unsure, feel free to reach out to us on our official LinkedIn Company Page.
  • We only communicate through official CookUnity channels. That means emails ending in @cookunity.com and interviews held through official company platforms (Google Meet or Zoom) — never WhatsApp, Telegram, or SMS.
  • We’ll never ask for payment or personal financial details. If anyone does, please don’t share any information and let us know right away.

If something ever feels off or you’re unsure about a message, we’d much rather you double-check with us. You can always contact us directly through any of our social media channels. We appreciate your interest in joining CookUnity — and we care about keeping your experience (and safety) as genuine as possible.

Top Skills

AWS
Azure
Burp Suite
Docker
Fortify
GCP
Java
Kotlin
Kubernetes
Oauth2
Oidc
SAML
Typescript
Veracode

Similar Jobs

2 Days Ago
Easy Apply
Remote
3 Locations
Easy Apply
145K-200K Annually
Senior level
145K-200K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
The role involves conducting application security reviews, threat modeling, code reviews, and vulnerability research, while also enhancing secure development practices and workflows.
Top Skills: BrakemanBurpsuiteGitGoRuby On Rails
12 Hours Ago
Remote
USA
94K-156K Annually
Mid level
94K-156K Annually
Mid level
Fintech
This role involves integrating security into software development, conducting vulnerability assessments, training staff in secure coding, and managing security policies.
Top Skills: AgileAspmCi/CdCloud EnvironmentsDastDevOpsIastSastSca
22 Days Ago
In-Office or Remote
5 Locations
155K-245K Annually
Senior level
155K-245K Annually
Senior level
Aerospace • Artificial Intelligence • Hardware • Machine Learning • Software • Defense • Manufacturing
The Senior Application Security Engineer will enhance security for software products, conduct code reviews, and implement compliance requirements with NIST and FedRAMP High standards.
Top Skills: AWSBurp SuiteCloud Platforms (AzureElixirGoGoogle Cloud)Python

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account