Zip

The future of B2B spend

Senior Application Security Engineer

$160K - $200KSan Francisco, CA, US
Job type
Full-time
Role
Engineering, Backend
Experience
3+ years
Visa
Will sponsor
Apply to Zip and hundreds of other fast-growing YC startups with a single profile.
Apply to role ›

About the role

The Security team at Zip is responsible for protecting the confidentiality and integrity of our customers’ data. As our first Application Security Engineer, you will take on a dynamic and high impact role. You will lead our efforts to build foundational security guardrails, launch key security initiatives, and solidify trust customers place in us. Your contributions will be pivotal to the success of Zip’s rapid growth as we launch new products, such as AI Agents and an App Marketplace, and enter into new markets, including EMEA and the Federal government space. We move quickly to solve a wide range of complex technical and product challenges. While we are an experienced team that can provide constant guidance and mentorship, we value engineers who can autonomously scope and solve complex technical challenges.

You will

  • Design and implement technical controls to eliminate or mitigate classes of security vulnerabilities.
  • Support the development of secure products through design reviews, threat models, static/dynamic scans, and hands-on security assessments.
  • Validate, triage, and coordinate security findings from bug bounty and third party pentests.
  • Mentor security analysts and security champions on security best practices and techniques.

Qualifications

  • Experience writing production-quality code for security tooling and services
  • Strong written and verbal communication with internal and external stakeholders
  • A solid understanding of security risks and the ability to balance security with business requirements
  • Experience with web applications, APIs, and cloud environments. At Zip, our stack includes Python, React, GraphQL, Kubernetes, and AWS

Nice to haves

  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP
  • Hands-on experience in offensive security (eg, through bug bounty programs or CTFs)

About Zip

Who we are:

Our cofounders started Zip in 2020 to address this seemingly intractable problem with a purpose-built procurement platform that provides a simple, consumer-grade user experience. Within just a few short years, Zip created the procurement orchestration category and developed the leading solution in this $50B+ TAM space. Today, leading companies like Instacart, Anthropic, Sephora, Discover, Reddit, and Lyft rely on Zip to manage billions of dollars in spend.

We're a fast-growing team that helped scale category-defining companies like Airbnb, Facebook, Salesforce, Apple, and Google. With a $2.2 billion valuation and $370 million in funding from Y Combinator, BOND, DST Global, and CRV, we’re focused on developing cutting-edge technology, expanding into new global markets, and—above all–driving incredible value for our customers.

Zip
Founded:2020
Batch:S20
Team Size:500
Status:
Active
Location:San Francisco
Founders
Lu Cheng
Lu Cheng
Founder
Rujul Zaparde
Rujul Zaparde
Founder