CookUnity Logo

CookUnity

Senior Application Security Engineer

Reposted 15 Days Ago
In-Office or Remote
Hiring Remotely in Latham, NY
Senior level
In-Office or Remote
Hiring Remotely in Latham, NY
Senior level
Lead application security efforts, perform security assessments, code reviews, and collaborate with development teams to remediate vulnerabilities. Promote secure coding practices and integrate security testing into CI/CD pipelines.
The summary above was generated by AI
About CookUnity:

Food has lost its soul to modern convenience. And with it, it has lost the power to nourish, inspire, and connect us. So in 2018, CookUnity was founded as the first-of-its-kind platform that connects the world with the source of truly great food: chefs. Today, CookUnity delivers 50 million meals a year from the industry’s best chefs to homes all over the country. Fresh. Ready-to-eat. And crafted with the passion that nourishes body and soul.

Unwilling to stop there, CookUnity is expanding beyond delivery to become an ever-innovating marketplace focused on our singular mission: empower Chefs to nourish the world.

If that mission has you hungry in more ways than one, you’ve found the right job posting.

The Role:

Become a founding member of the Application Security team at CookUnity. You’ll work closely with disparate groups inside of CookUnity’s engineering organization, ranging from our Infrastrcuture and Software Engineering teams to ensure were free from high risk vulnerabilities but also building secure by design solutions.

Responsibilities:
  • Lead application security efforts by performing security assessments, code reviews, and penetration testing focused on applications developed in Kotlin, Java, and TypeScript.
  • Identify, classify, prioritize, and track remediation of vulnerabilities such as those listed in the OWASP Top 10 and other common weaknesses.
  • Use and maintain application security tools such as Burp Suite for dynamic testing, SAST/DAST/IAST tools, and other automated security scanners.
  • Collaborate closely with software development teams to enforce secure coding standards and hold Software Engineers accountable for patching vulnerabilities within defined SLAs.
  • Integrate security testing and automation into CI/CD pipelines to ensure continuous security validation.
  • Define and maintain security requirements and best practices aligned with industry standards such as OWASP, NIST, ISO, PCI DSS, and GDPR.
  • Conduct threat modeling, risk assessments, and security design reviews for new and existing applications.
  • Promote security awareness and provide training to development teams on secure coding and vulnerability mitigation.
  • Respond to security incidents and support remediation efforts.
  • Recommend and implement new security tools and technologies to improve application security posture.
  • Work in Agile and DevSecOps environments to embed security throughout the software development lifecycle.
Minimum Requirements:
  • Bachelor’s degree in Computer Science, Cybersecurity, or related field.
  • 6-8+ years of experience in application security, secure coding, and vulnerability assessment.
  • Strong development background with hands-on experience in Kotlin, Java, and Typescript.
  • Deep understanding of OWASP Top 10, CWE, and common web and API vulnerabilities.
  • Proficient with security testing tools such as Burp Suite, Fortify, Veracode, or similar.
  • Experience with secure SDLC, DevSecOps practices, and integrating security into CI/CD pipelines.
  • Familiarity with authentication and authorization protocols like OAuth2, OIDC, and SAML.
  • Ability to work effectively with development teams, guiding and holding them accountable for timely vulnerability remediation.
  • Relevant certifications such as CISSP, CSSLP, OSCP, GWAPT.
  • Fluency in English.
Preferred Requirements:
  • Knowledge of cloud security (AWS, GCP, Azure) and container security (Docker, Kubernetes) is a plus.
Benefits:

💸 Get paid in USD.

🗺 Work remotely: design the life that you want.

⛱ Enjoy 15 business days of vacation each year from the start date.

🎄16 fully paid Argentinean holidays.

🩺 Healthcare Benefit: Monthly stipend to use in your preferred healthcare provider.

🗓️ 5-year Sabbatical: After 5 years with CookUnity, you get a 4-week paid sabbatical.

🐣 Paid family leave.

🕯 Compassionate Leave: 3-5 days each time the need arises.

🧘🏽‍♀️ Customize the benefits that suit your needs! Access a range of perks tailored to you, including learning opportunities, wellness memberships, delivery apps, and more through our comprehensive benefit platform.

🧑‍🏫 Personalized English coach.



Learn More About CookUnity:

We believe great leadership starts with alignment on vision, values, and ways of working. To give you deeper insight into who we are and what we’re looking for, we invite you to explore: CookUnity's Leadership Principles – The values and behaviors that guide how we operate, collaborate, and scale.

We hope this provides valuable insight into our culture and product vision. If this excites you, we’d love to connect!



If you’re interested in this role, please submit your application and if we think you might be a fit, we'll get in touch with you. Thank you for your time!

CookUnity is an Equal Opportunity Employer. We are dedicated to creating a community of inclusion and an environment free from discrimination or harassment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, citizenship status, protected veteran status, genetic information, or physical or mental disability.

Top Skills

AWS
Azure
Burp Suite
Docker
Fortify
GCP
Java
Kotlin
Kubernetes
Typescript
Veracode

Similar Jobs

5 Days Ago
In-Office or Remote
New York, NY, USA
150K-180K Annually
Senior level
150K-180K Annually
Senior level
Food
Lead application security efforts by performing assessments, code reviews, penetration testing, and promoting secure coding practices within the engineering teams.
Top Skills: AWSAzureBurp SuiteDockerFortifyGCPJavaKotlinKubernetesOauth2OidcSAMLTypescriptVeracode
Yesterday
Remote or Hybrid
United States
Senior level
Senior level
Aerospace
As a Security Engineer, you'll design and harden systems in classified environments, deploy secure enclaves, and ensure compliance. You'll handle secure CI/CD processes, threat modeling, and vulnerability management while automating compliance enforcement and supporting incident response.
Top Skills: AnsibleBashCi/CdCis BenchmarksDevsecopsDisa StigsGoHybrid Iam SolutionsIacLinuxPythonTerraformYaml
24 Days Ago
In-Office or Remote
5 Locations
155K-245K
Senior level
155K-245K
Senior level
Aerospace • Artificial Intelligence • Hardware • Machine Learning • Software • Defense
The Senior Application Security Engineer will enhance security for software products, conduct code reviews, and implement compliance requirements with NIST and FedRAMP High standards.
Top Skills: AWSBurp SuiteCloud Platforms (AzureElixirGoGoogle Cloud)Python

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account