Skip to content
mimi

Sr. Security Engineer

Aha!

Remote · Canada Full-time Senior $110k – $190k/yr Today

About the role

About Aha

Aha is the world's #1 product development software. We help more than 1 million product builders to bring their strategy to life. Our integrated tools empower teams to go from discovery to delivery. The suite includes Aha Roadmaps, Aha Discovery, Aha Ideas, Aha Whiteboards, Aha Builder, Aha Develop, Aha Teamwork, and Aha Knowledge. Product teams rely on our expertise, AI assistant, and training programs via Aha Academy to do their best work.

We are proud to be a very different type of high-growth SaaS company. The business is self-funded, profitable, and 100% remote. We are recognized as one of the best fully remote companies to work for, champion the Bootstrap Movement, and have given over $1.5M to people in need through Aha Cares. Learn more at www.aha.io.

Our Team

The Aha engineering team is a midsized, fully remote group that is highly productive. We are centered around North American time zones so we can collaborate during the workday.

  • We help each other grow: We each bring unique skills to the table and want our teammates to feel valued from the start. Our onboarding program exposes new hires to the codebase and lets them contribute right away.
  • We move quickly: We ship code multiple times a day. We believe in getting valuable features in front of customers and iteratively improving as we learn what works and what does not.
  • We value product over process: We want the team to have the time and focus needed to solve complex challenges. We minimize overhead by setting clear goals and avoiding heavyweight processes and excessive meetings.
  • We share knowledge freely: We share our learnings with one another and with the developer community. Our engineering blog demonstrates how we tackle interesting challenges at Aha.
  • We enjoy: We like what we do. And we want you to love your team and your job too. Learn more about The Responsive Method, our company values, and the generous benefits we offer.

Our Technology

  • Backend: Single‑instance, multitenant Ruby on Rails monolith supported by Postgres (database), Redis (background jobs), Kafka (event processing), and Memcached (Rails caching).
  • Real‑time services: Node.js webserver to support collaborative editing and real‑time updates.
  • Infrastructure: Hosted on Amazon Web Services and architected with ECS for reproducibility and scalability.
  • Frontend: Growing amount of React to build rich client‑side experiences, including our fully collaborative text editor and slide presentation editor.
  • Approach: Balance Rails for conventions and simplicity with React for powerful interactive functionality.
  • Planning & Collaboration: Primarily in Aha Roadmaps and built Aha Develop for engineers. Use Slack and Zoom for video calls (email rarely).

Your Experience

The primary focus of this role is web application security, so you should be deeply knowledgeable about vulnerabilities and mitigations. You are familiar with securing data in multitenant architectures and have helped engineers build secure applications.

Skills

  • Four+ years of experience working in application security
  • Active collaborator with engineering and product teams
  • Experience with security reviews or threat modeling for a full‑stack web application
  • Experience with security tools such as CodeQL or Burp Suite
  • Experience with Ruby on Rails is a plus
  • Kind, humble, eager to learn, and always willing to help others
  • Enjoy solving problems regardless of the technologies and techniques involved
  • Have worked at meaningful scale before and want to do so again

Your Work at Aha

About

The security team works across our suite of products and provides guidance for the larger engineering team across the full stack. We are passionate about data security and helping each other. As a Senior Security Engineer, your work will include:

  • Identifying application security threats and mitigations early
  • Improving and maintaining security code scanning tools
  • Contributing to application security scanning or testing
  • Developing and sharing secure patterns internally for ongoing education

If the Sr. Security Engineer role sounds appealing, we would love to hear from you. (A real human reviews every application.)

Grow with Us

Everyone deserves to reach their fullest potential. We know that when we do work that matters with people we care about in a high‑growth environment, we feel engaged and alive. It is why we joined Aha and how we achieve our very best.

Benefits

  • Base salary range for this role in the U.S. is between $110,000 and $190,000
  • Cash‑based compensation includes profit sharing, and we contribute a percentage of your total pay each month toward your retirement
  • Medical, dental, and vision plans (for many teammates, we cover 100% of the premiums)
  • Up to 200 hours of paid time off a year to spend however you want
  • 30 to 90 days of paid parental leave and 5 to 10 days of paid care and bereavement leave
  • Up to $1,000 annually for third‑party education, along with paid time off to immerse yourself in learning
  • Volunteer opportunities throughout the year

Base salary and total compensation are dependent upon many factors, including skills, experience, and relevant past roles.

Requirements

  • Four+ years of experience working in application security
  • Active collaborator with engineering and product teams
  • Experience with security reviews or threat modeling for a full-stack web application
  • Experience with security tools such as CodeQL or Burp Suite
  • Experience with Ruby on Rails is a plus

Responsibilities

  • Identifying application security threats and mitigations early
  • Improving and maintaining security code scanning tools
  • Contributing to application security scanning or testing
  • Developing and sharing secure patterns internally for ongoing education

Benefits

profit sharingretirement contributionmedical dental and vision plans (premiums covered)up to 200 hours paid time off per year30-90 days paid parental leave5-10 days paid care and bereavement leaveup to $1,000 annual education stipendvolunteer opportunities

Skills

Application securityThreat modelingSecurity reviewsCodeQLBurp SuiteRuby on Rails

Don't send a generic resume

Paste this job description into Mimi and get a resume tailored to exactly what the hiring team is looking for.

Get started free