Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Security Engineer - Application Security  image - Rise Careers
Job details

Principal Security Engineer - Application Security

 


About Gusto

Gusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools. Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000 businesses nationwide.

Our mission is to create a world where work empowers a better life, and it starts right here at Gusto. That’s why we’re committed to building a collaborative and inclusive workplace, both physically and virtually. Learn more about our Total Rewards philosophy

About the role:

The Security Engineering role works with product and engineering leads to design products and features with the safety and privacy of our customers in mind. Candidates for this role will be joining a team focused on building long-term relationships between the Security team and internal stakeholders across the company, providing guidance on security risks and mitigation, and secure development architecture. More about Security Partners on the Gusto blog.

The Product Security group helps Gusto move faster, securely. We’re a team of engineers who work to enable other teams to build products as quickly as possible while continuing to protect our customers. We support developers in shipping secure code by building security tools and services, providing security training and expertise, and advocating for best practices in authentication, authorization, and safe data handling across the company.

Here’s what you’ll do day-to-day:

  • Work alongside product, engineering, infrastructure, legal, and privacy teams to design safe features to protect our customers.
  • Review and threat model new systems, products, and features.
  • Provide detailed security advice and risk assessments, including architectural direction.
  • Develop guidelines and recommendations for secure coding practices.
  • Lead and manage secure code training instruction.
  • Implement and deploy application security tools.
  • Develop long-term relationships with product development and engineering teams.

Here’s what we're looking for:

  • 12+ years of experience in information security, especially application security, product security, and/or security partnership.
  • 5+ years of hands on software development experience 
  • Ability to work with engineers to balance security risks, customer privacy, and business requirements.
  • Experience building software. We primarily use Ruby, JavaScript, Python, and Kotlin.

Our cash compensation amount for this role is targeted at $225,000/yr to $245,000/yr in Denver & most remote locations, and $265,000/yr to $285,000/yr in New York & San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.


Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.

Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas. 

When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required.


Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Gusto. 

Gusto is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Gusto considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gusto is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. We want to see our candidates perform to the best of their ability. If you require a medical or religious accommodation at any time throughout your candidate journey, please fill out this form and a member of our team will get in touch with you.

Gusto takes security and protection of your personal information very seriously. Please review our Fraudulent Activity Disclaimer.

Average salary estimate

$255000 / YEARLY (est.)
min
max
$225000K
$285000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Security Engineer - Application Security , Gusto, Inc.

As a Principal Security Engineer - Application Security at Gusto, you'll be at the forefront of protecting our customers while working with a dynamic team dedicated to the mission of empowering small businesses. Gusto is not just about payroll; we’re a full-service people platform catering to over 300,000 businesses. Your role will involve partnering with product and engineering leads to ensure that safety and privacy are prioritized in every feature we roll out. You’ll engage with various teams and provide security guidance, helping mitigate risks while enabling innovation. With your extensive experience in information security and application security, you’ll assess new systems and products, develop secure coding practices, and lead training initiatives to enhance our security culture. Plus, your system threat modeling expertise will steer architectural directions that prioritize user safety. Collaboration is key—your relationships with development and engineering teams will be crucial in intertwining security with their workflows. Join us in San Francisco and be part of a supportive, inclusive environment that embraces diverse perspectives as we build tools to help small businesses thrive. If you want to use your passion for security to make a real difference, Gusto is the place for you!

Frequently Asked Questions (FAQs) for Principal Security Engineer - Application Security Role at Gusto, Inc.
What does a Principal Security Engineer - Application Security do at Gusto?

At Gusto, a Principal Security Engineer - Application Security is responsible for ensuring that our products are developed with safety and privacy in mind. They work closely with teams across the company, offering security guidance, conducting risk assessments, and creating guidelines for secure coding practices.

Join Rise to see the full answer
What qualifications do I need for the Principal Security Engineer - Application Security position at Gusto?

Candidates should have at least 12 years of experience in information security, focusing on application security and product security. Additionally, 5 years of hands-on software development experience is crucial, particularly with languages like Ruby, JavaScript, Python, and Kotlin.

Join Rise to see the full answer
What is the work environment like for a Principal Security Engineer at Gusto?

Gusto promotes a collaborative and inclusive work environment. In-person roles, such as Principal Security Engineer - Application Security, require some days in the office, fostering teamwork while also supporting flexible remote arrangements.

Join Rise to see the full answer
How does Gusto support professional development for the Principal Security Engineer position?

Gusto is committed to helping employees grow their skills. For a Principal Security Engineer - Application Security, that might include security training sessions, attending conferences, and resources to stay updated on the latest security practices and technologies.

Join Rise to see the full answer
What impact does the Principal Security Engineer have on businesses using Gusto?

The Principal Security Engineer - Application Security directly influences how businesses trust our platform. By designing secure features and tools, they help ensure our customers' data privacy and security, strengthening the overall integrity of Gusto.

Join Rise to see the full answer
Is remote work an option for the Principal Security Engineer role at Gusto?

Yes, while the Principal Security Engineer - Application Security position will require some in-office work in our San Francisco location, we also offer flexible remote work options where applicable, provided you have a reliable internet connection.

Join Rise to see the full answer
What is Gusto's approach to diversity for the Principal Security Engineer role?

Gusto values diversity and seeks candidates from all backgrounds for the Principal Security Engineer - Application Security role. The company believes that a diverse workforce strengthens our community and enhances innovation.

Join Rise to see the full answer
Common Interview Questions for Principal Security Engineer - Application Security
What security methodologies do you prefer when assessing new systems?

In your answer, focus on frameworks like STRIDE or DREAD. Explain how you apply these methodologies to identify vulnerabilities and mitigate risks effectively.

Join Rise to see the full answer
Can you describe your experience with secure coding practices?

Discuss specific examples of secure coding practices you've implemented or taught. Emphasize your ability to collaborate with developers to instill these practices in their workflows.

Join Rise to see the full answer
How do you stay updated on the latest security threats?

Mention resources such as security blogs, webinars, and industry conferences. Highlight specific tactics you use to ensure that your knowledge remains current.

Join Rise to see the full answer
Describe a time when you dealt with a significant security incident.

Share a detailed example of a security incident. Explain your approach to investigation, remediation, and how the experience shaped your future security practices.

Join Rise to see the full answer
What tools and technologies do you find most effective for application security?

Name particular tools (like static analysis tools, dynamic scanning tools, etc.) and explain why you prefer them and how they enhance security in the development process.

Join Rise to see the full answer
How do you balance security needs with business requirements?

Discuss your approach to risk management, highlighting how you communicate with stakeholders to find a middle ground between security and business objectives effectively.

Join Rise to see the full answer
How would you educate a non-technical team on security best practices?

Share your strategies for simplifying complex security topics for non-technical teams. Provide examples of training programs or materials you've developed.

Join Rise to see the full answer
What is your experience with application security in a cloud environment?

Talk about your experiences working with cloud providers. Discuss your understanding of cloud security principles and compliance requirements.

Join Rise to see the full answer
Can you provide an example of a successful security feature you designed?

Outline a project where you implemented a significant security feature. Discuss the challenges faced, your design approach, and the positive results of the implementation.

Join Rise to see the full answer
What do you consider to be the most challenging aspect of application security?

Reflect on industry trends, such as the shift to DevOps or cloud-native applications, and how this evolution presents unique challenges in ensuring applications are secure.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Gusto, Inc. Remote Denver, CO;San Francisco, CA;New York, NY;Los Angeles, CA
Posted 11 days ago
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Performance Bonus
Paid Holidays
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Posted 11 days ago
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Learning & Development
Equity
Paid Holidays
Paid Time-Off
WFH Reimbursements
Child Care stipend
Maternity Leave
Paternity Leave
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Brex Remote New York, New York, United States
Posted 11 days ago
Customer-Centric
Growth & Learning
Collaboration over Competition
Inclusive & Diverse
Rapid Growth
Dental Insurance
Vision Insurance
401K Matching
Maternity Leave
Paternity Leave
Flex-Friendly
Medical Insurance
Equity
Photo of the Rise User
Posted 2 days ago

Gusto was founded in 2011. This company provides payroll processing and employee benefits services. Their headquarters are located in San Francisco, California.

118 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
SALARY RANGE
$225,000/yr - $285,000/yr
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
November 29, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!