About the job
About Infiterra
Join us in revolutionizing the subscription economy by streamlining the delivery of subscription services.
Infiterra empowers IT distributors, Managed Service Providers (MSPs), and telecommunications companies to thrive in the subscription landscape. Our cutting-edge subscription commerce platform automates and integrates subscription workflows, from quote to billing, enhancing operational efficiency, ensuring billing accuracy, and enabling scalable growth.
As a recognized global frontrunner in subscription commerce, Infiterra melds innovation, performance excellence, and trusted expertise to assist our partners in their transformation and growth journeys.
About the Role
We are seeking a proactive Senior Application Security Engineer who will embed security into our software design, development, and operational processes, not as an afterthought, but as an integral part of our daily engineering practices. You will engage directly with product and engineering teams to identify risks early, enhance secure-by-design methodologies, and consistently elevate our application security standards. This role is highly practical, closely interfacing with code and architecture, and deeply integrated into the Software Development Life Cycle (SDLC).
Your Responsibilities
Integrate security within the SDLC
Incorporate security measures across all SDLC phases: requirements gathering, design, implementation, testing, deployment, and maintenance.
Collaborate closely with engineering teams to ensure adherence to secure development practices.
Evaluate security controls for new features, services, and architectural modifications.
Threat Modeling and Secure Design
Facilitate threat modeling sessions (e.g., STRIDE) for both new and existing systems.
Identify potential threats, attack vectors, misconfigurations, and insecure design patterns.
Work alongside engineers to ensure systems adhere to secure-by-design principles.
Secure Code and Architecture Reviews
Conduct security-focused code reviews to pinpoint vulnerabilities and risky implementations.
Offer clear and actionable guidance on secure coding patterns and best practices.
Assess application and system architectures from a security standpoint.
Security Testing and Tooling
