About the job
About Lucidya
Lucidya is a cutting-edge Customer Experience Intelligence platform powered by AI, enabling businesses to deeply understand, engage with, and retain their customers at scale. As we expand our global footprint, we prioritize building secure-by-design products. Security is a fundamental principle within our engineering strategy, and we are making significant investments to enhance our application security posture across all products and platforms.
In line with this growth, we are seeking an Application Security Engineer to champion secure development practices, proactively pinpoint vulnerabilities, and integrate security throughout the software development lifecycle.
About the Role
This represents the inaugural dedicated Application Security role at Lucidya, making it a high-impact and foundational position. You will be instrumental in shaping Lucidya’s application security strategy, collaborating closely with engineering teams to identify risks, mitigate security gaps, and ensure our applications are designed with security as a priority.
Your role will bridge security engineering, software development, and cloud infrastructure, allowing you to think like an attacker while empowering developers to create secure, scalable systems.
What You’ll Be Doing
Core Responsibilities
- Develop and implement automated security testing and vulnerability detection workflows integrated into the Software Development Lifecycle (SDLC).
- Conduct security reviews of web applications, mobile applications, APIs, and cloud environments (both public and private).
- Perform penetration testing on web, mobile, API, and desktop applications, along with their supporting infrastructure.
- Evaluate application defenses, identify architectural and design-level security weaknesses, and propose effective mitigation strategies.
- Adopt an attacker’s mindset to proactively discover vulnerabilities and complex security risks before they reach production.
- Collaborate closely with engineering teams to promote secure coding practices and security-aware development.
- Conduct code reviews with a focus on security, especially for critical services and deployments.
- Stay abreast of emerging threats and contribute to the development or adoption of innovative security tools and techniques.
Day-to-Day Responsibilities
- Review application code and architecture from a security viewpoint.
- Guide teams on secure development lifecycle (SDLC) practices.
- Work alongside developers during feature development and releases to ensure security controls are implemented.
- Participate in threat modeling, vulnerability triage, and remediation tracking.
- Contribute to the definition and evolution of Lucidya’s application security strategy.
Success Metrics
- Demonstrable reduction in application vulnerabilities, in line with findings from external security assessments.
- Successful and secure application releases with minimal security flaws.
