
Principal Security Engineer - Application Security
Gusto, Inc.Job Location
Salary Range
Job Summary
The Security Engineering role at Gusto involves designing products with safety and privacy in mind, working closely with product, engineering, infrastructure, legal, and privacy teams to protect customers. The team provides security guidance, threat modeling, and secure coding practices, while also building security tools and services. This is a long-term relationship-focused position that requires 12+ years of experience in information security and hands-on software development experience. Gusto offers competitive compensation, including $225,000-$285,000 per year, stock equity, and flexible remote work options. The role involves leading secure code training instruction and implementing application security tools.
About the role:
The Security Engineering role works with product and engineering leads to design products and features with the safety and privacy of our customers in mind. Candidates for this role will be joining a team focused on building long-term relationships between the Security team and internal stakeholders across the company, providing guidance on security risks and mitigation, and secure development architecture. More about Security Partners on the Gusto blog.
The Product Security group helps Gusto move faster, securely. We’re a team of engineers who work to enable other teams to build products as quickly as possible while continuing to protect our customers. We support developers in shipping secure code by building security tools and services, providing security training and expertise, and advocating for best practices in authentication, authorization, and safe data handling across the company.
Here’s what you’ll do day-to-day:
Work alongside product, engineering, infrastructure, legal, and privacy teams to design safe features to protect our customers.
Review and threat model new systems, products, and features.
Provide detailed security advice and risk assessments, including architectural direction.
Develop guidelines and recommendations for secure coding practices.
Lead and manage secure code training instruction.
Implement and deploy application security tools.
Develop long-term relationships with product development and engineering teams.
Here’s what we're looking for:
12+ years of experience in information security, especially application security, product security, and/or security partnership.
5+ years of hands on software development experience
Ability to work with engineers to balance security risks, customer privacy, and business requirements.
Experience building software. We primarily use Ruby, JavaScript, Python, and Kotlin.
Our cash compensation amount for this role is targeted at $225,000/yr to $245,000/yr in Denver & most remote locations, and $265,000/yr to $285,000/yr in New York & San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.