About the job
About Infiterra
Be a part of our journey to revolutionize the subscription economy by streamlining subscription service delivery.
Infiterra empowers IT distributors, Managed Service Providers (MSPs), and telecommunications companies to thrive in the subscription economy. Our comprehensive subscription commerce platform automates and integrates subscription workflows—from quoting to billing—enhancing operational efficiency, ensuring billing accuracy, and fostering scalable growth.
As a recognized global leader in subscription commerce, Infiterra blends innovation, exceptional performance, and trusted expertise to assist our partners in transforming and advancing their business.
About the Role
We are in search of a Senior Application Security Engineer who will integrate security throughout our software design, development, and operational processes; prioritizing it as a core component rather than an afterthought. You will collaborate closely with product and engineering teams to identify risks early on, enhance secure-by-design methodologies, and continuously elevate our application security standards. This role is hands-on and closely tied to code, architecture, and the Software Development Life Cycle (SDLC). This position is fully remote.
Key Responsibilities
Integrate Security into the SDLC
Incorporate security practices across all phases of the SDLC: requirements, design, implementation, testing, deployment, and maintenance.
Collaborate closely with engineering teams to ensure consistent application of secure development practices.
Evaluate security controls for new features, services, and architectural changes.
Threat Modeling & Secure Design
Conduct threat modeling sessions (e.g., STRIDE) for new and existing systems.
Identify threats, attack vectors, misconfigurations, and insecure design patterns.
Work with engineers to ensure systems adhere to secure-by-design principles.
Secure Code & Architecture Reviews
Perform security-focused code reviews to detect vulnerabilities and risky implementations.
Offer clear, actionable recommendations on secure coding practices.

