Sr. Security Engineer
Aha!
About the role
About Aha
Aha is the world's #1 product development software. We help more than 1 million product builders to bring their strategy to life. Our integrated tools empower teams to go from discovery to delivery. The suite includes Aha Roadmaps, Aha Discovery, Aha Ideas, Aha Whiteboards, Aha Builder, Aha Develop, Aha Teamwork, and Aha Knowledge. Product teams rely on our expertise, AI assistant, and training programs via Aha Academy to do their best work.
We are proud to be a very different type of high-growth SaaS company. The business is self-funded, profitable, and 100% remote. We are recognized as one of the best fully remote companies to work for, champion the Bootstrap Movement, and have given over $1.5M to people in need through Aha Cares. Learn more at www.aha.io.
Our Team
The Aha engineering team is a midsized, fully remote group that is highly productive. We are centered around North American time zones so we can collaborate during the workday.
- We help each other grow: We each bring unique skills to the table and want our teammates to feel valued from the start. Our onboarding program exposes new hires to the codebase and lets them contribute right away.
- We move quickly: We ship code multiple times a day. We believe in getting valuable features in front of customers and iteratively improving as we learn what works and what does not.
- We value product over process: We want the team to have the time and focus needed to solve complex challenges. We minimize overhead by setting clear goals and avoiding heavyweight processes and excessive meetings.
- We share knowledge freely: We share our learnings with one another and with the developer community. Our engineering blog demonstrates how we tackle interesting challenges at Aha.
- We enjoy: We like what we do. And we want you to love your team and your job too. Learn more about The Responsive Method, our company values, and the generous benefits we offer.
Our Technology
- Backend: Single‑instance, multitenant Ruby on Rails monolith supported by Postgres (database), Redis (background jobs), Kafka (event processing), and Memcached (Rails caching).
- Real‑time services: Node.js webserver to support collaborative editing and real‑time updates.
- Infrastructure: Hosted on Amazon Web Services and architected with ECS for reproducibility and scalability.
- Frontend: Growing amount of React to build rich client‑side experiences, including our fully collaborative text editor and slide presentation editor.
- Approach: Balance Rails for conventions and simplicity with React for powerful interactive functionality.
- Planning & Collaboration: Primarily in Aha Roadmaps and built Aha Develop for engineers. Use Slack and Zoom for video calls (email rarely).
Your Experience
The primary focus of this role is web application security, so you should be deeply knowledgeable about vulnerabilities and mitigations. You are familiar with securing data in multitenant architectures and have helped engineers build secure applications.
Skills
- Four+ years of experience working in application security
- Active collaborator with engineering and product teams
- Experience with security reviews or threat modeling for a full‑stack web application
- Experience with security tools such as CodeQL or Burp Suite
- Experience with Ruby on Rails is a plus
- Kind, humble, eager to learn, and always willing to help others
- Enjoy solving problems regardless of the technologies and techniques involved
- Have worked at meaningful scale before and want to do so again
Your Work at Aha
About
The security team works across our suite of products and provides guidance for the larger engineering team across the full stack. We are passionate about data security and helping each other. As a Senior Security Engineer, your work will include:
- Identifying application security threats and mitigations early
- Improving and maintaining security code scanning tools
- Contributing to application security scanning or testing
- Developing and sharing secure patterns internally for ongoing education
If the Sr. Security Engineer role sounds appealing, we would love to hear from you. (A real human reviews every application.)
Grow with Us
Everyone deserves to reach their fullest potential. We know that when we do work that matters with people we care about in a high‑growth environment, we feel engaged and alive. It is why we joined Aha and how we achieve our very best.
Benefits
- Base salary range for this role in the U.S. is between $110,000 and $190,000
- Cash‑based compensation includes profit sharing, and we contribute a percentage of your total pay each month toward your retirement
- Medical, dental, and vision plans (for many teammates, we cover 100% of the premiums)
- Up to 200 hours of paid time off a year to spend however you want
- 30 to 90 days of paid parental leave and 5 to 10 days of paid care and bereavement leave
- Up to $1,000 annually for third‑party education, along with paid time off to immerse yourself in learning
- Volunteer opportunities throughout the year
Base salary and total compensation are dependent upon many factors, including skills, experience, and relevant past roles.
Requirements
- Four+ years of experience working in application security
- Active collaborator with engineering and product teams
- Experience with security reviews or threat modeling for a full-stack web application
- Experience with security tools such as CodeQL or Burp Suite
- Experience with Ruby on Rails is a plus
Responsibilities
- Identifying application security threats and mitigations early
- Improving and maintaining security code scanning tools
- Contributing to application security scanning or testing
- Developing and sharing secure patterns internally for ongoing education
Benefits
Skills
Don't send a generic resume
Paste this job description into Mimi and get a resume tailored to exactly what the hiring team is looking for.
Get started free