Staff Software Engineer, Product Security
Our Product Security team supports the following tenet of Slack’s mission: make people’s working lives more secure. We’re serious about protecting our infrastructure, operations, and most importantly our customers’ data. We take a systemic approach to security and strive to ensure we provide low friction, high impact security across everything we do. As a member of the Product Security team, you care about shipping secure products and protecting Slack’s users from bad actors. You are passionate about enabling our developers to deliver new features securely. You think about your job as not just identifying individual vulnerabilities but also finding effective ways to eliminate whole classes of them. Your work will directly impact the way millions of people, teams, and businesses get things done using Slack.
Slack has a positive, diverse, and supportive culture—we look for people who are curious, inventive, and working to be a little better every single day. In our work environment, we aim to be smart, humble, hardworking and, above all, collaborative. If this sounds like a good fit for you, why not say hello?
What you will be doing
- Contributing security-focused feedback to engineers during all phases of the development lifecycle
- Performing technical security assessments on our web applications, native clients, internal services, and partner applications
- Efficiently scoping blackbox, whitebox, and graybox assessments to optimize security review time and resources
- Seeking out opportunities to automate processes when appropriate
- Scaling the impact of our team through direct mentorship of our more junior team members
- Communicating risks to engineering staff through training and technical demonstration of vulnerabilities and secure design patterns
- Maintaining and creating secure development practices and programs for our engineering teams and external developers
- Acting as an ambassador for security within Slack
- Serving as a public representative for security at Slack by engaging periodically in internal and external speaking engagements
- Identifying emerging classes of vulnerabilities and developing solutions for them before they’re a problem
What you should have
- Bachelor’s degree in Computer Science, Engineering or related field, or equivalent training, fellowship, or work experience
- 5+ years experience in security testing of web applications and native apps
- Deep understanding of web application architecture and design principles
- Strong written and verbal communication skills and ability to communicate with empathy when delivering constructive feedback regarding security matters to engineers and product designers
- Familiarity with common web application testing tools for DAST, SAST, and IAST analysis such as Burp Suite, Checkmarx, Veracode
- Knowledge of authentication mechanisms like SAML, OAuth, etc.
- Knowledge of common security flaws and resolution as published by OWASP, SANS, etc.
- Knowledge of how to test code and applications across various platforms (iOS, Mac, Linux, Windows, Android, etc) for security and quality
- Ability to see patterns, commonalities and investigate complex issues
- Organizational skills to bring together and record detailed and accurate information about bugs and systemic issues
- Experience with Amazon AWS services and familiarity with Slack products is a plus
- Current or former security training or certifications such as SANS GWAPT or similar is a plus
- Public speaking engagements or published research is also a plus; a successful engineer in this role will be expected to represent Slack externally from time to time
- Though this is not primarily a development role, some background in software engineering in a collaborative and dynamic environment is a plus
Slack is a layer of the business technology stack that brings together people, data, and applications – a single place where people can effectively work together, find important information, and access hundreds of thousands of critical applications and services to do their best work. From global Fortune 100 companies to corner markets, businesses and teams of all kinds use Slack to bring the right people together with all the right information. Slack is headquartered in San Francisco, CA and has offices around the world. For more information on how Slack makes teams better connected, visit slack.com.
Ensuring a diverse and inclusive workplace where we learn from each other is core to Slack’s values. We welcome people of different backgrounds, experiences, abilities and perspectives. We are an equal opportunity employer and a pleasant and supportive place to work.
Come do the best work of your life here at Slack.