The opportunity
What you will own
- Lead application and API threat modelling across CloudTen products.
- Review authentication, authorization, session, secrets, cryptography and data-protection designs.
- Build practical security testing and CI/CD assurance into engineering workflows.
- Coordinate vulnerability triage, remediation validation and security release gates.
- Support incident readiness, logging, telemetry and secure forensic practices.
- Translate NIST, OWASP and other relevant frameworks into actionable engineering controls.
What you bring
Core qualifications
- Senior application-security or product-security engineering experience.
- Strong knowledge of web/API security, authentication, access control, secrets and cloud security.
- Practical experience with threat modelling, secure code review and vulnerability remediation.
- Ability to work directly with software engineers and influence architecture without blocking delivery.
- Strong written security documentation and risk communication.
Additional strengths
Preferred experience
- Experience with secure messaging, identity, healthcare or FinTech products.
- Experience with SAST/DAST/SCA, SBOMs and software supply-chain security.
- Experience with NIST SSDF, OWASP ASVS/SAMM or comparable secure-development frameworks.
Employment, compensation and fair recruitment
The published USD range is a U.S.-market reference range for this role. Final compensation, benefits, employment classification, payroll, tax treatment and statutory entitlements are determined by the employing entity, work location, experience and applicable law.
CloudTen does not charge candidates recruitment, placement, processing or employment fees. Qualified applicants are assessed against job-related requirements. Reasonable accommodation is available during recruitment where required by applicable law.
BYU-Pathway Worldwide students and graduates: qualified candidates are especially welcome to apply. Participation in recognised CloudTen talent-development or university programmes may receive positive consideration where lawful, while appointments remain merit-based and subject to the published requirements.




