Ibotta

Technology

SecurityEngineer

$115–130k Denver, Colorado, United States FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Security Engineer at Ibotta. Skills: Application Security, Vulnerability Management, Cloud Infrastructure, Secure AI Coding. Perform application security assessments. Perform manual code reviews”

Industry & Context.

Technology
Problems you'll solve

Problem-solving skills

Eligibility Requirements

24/7 on-call rotation, Relocation bonus

What They're Looking For.

Must Have

4+ years security engineering, 4+ years application development, 4+ years application security, Proficiency in Python, Proficiency in Go, Experience with Docker, Experience with Kubernetes, Understanding of CI/CD, Understanding of Web API security, Understanding of authentication protocols, Familiarity with OWASP Top 10, Working knowledge of web application testing tools, Ability to work effectively across organization, Collaborate effectively with technical teams, Collaborate effectively with non-technical teams, Excellent oral communication skills, Excellent written communication skills, Effective problem-solving skills, Experience building custom security tooling, Experience building automation scripts

Nice to Have

Basic knowledge of networking security, Knowledge of AWS security services, Knowledge of IaC, Experience writing secure IAM policies, Experience writing Terraform configurations, CompTIA SecAI+ certification, ECPPT certification, EWPT certification, GWAPT certification, OSCP certification, Similar certification

What You'll Do.

Perform application security assessments

Perform manual code reviews

Perform penetration testing

Mature bug bounty program

Analyze application architecture

Develop opportunities for improvement

Integrate tools within CI/CD

Manage tools within CI/CD

Develop secure coding practices

Provide training to developers

Design runtime security controls

Implement runtime security controls

Design container security controls

Implement container security controls

Automate infrastructure security checks

Evaluate security of AI-generated code

Implement guardrails for model-serving endpoints

Stay ahead of AI-specific threats

Participate in on-call rotation

Participate in incident response

Identify phishing attempts

Report security incidents

How You'll Work.

Team & Collaboration

Key stakeholders; Mobile team; Platform team; Infrastructure team; AI enablement team; Engineering team; Technical team members; Non-technical team members

Communication Scope

Oral communication; Written communication

Process & Methodology

CI/CD

Full Job Description

Ibotta is seeking a Security Engineer with a deep expertise in Application Security, Vulnerability Management, and Cloud Infrastructure to join our innovative team and contribute to our mission to Make Every Purchase Rewarding. In this role, you will be ensuring the security of our software development lifecycle (SDLC) and our cloud-native environments. A key focus of this position will be addressing the emerging security challenges posed by Artificial Intelligence (AI) technologies, specifically around secure AI coding practices and the infrastructure that supports AI/ML workloads.   This position is located in Denver, Colorado as a hybrid position requiring 3 days in office (Tuesday, Wednesday, and Thursday). Candidates must live in the United States.   Not based in Denver? We will offer a relocation bonus to help make your move to the Mile High City a smooth one.   WHAT YOU WILL BE DOING: - Perform application security assessments, including manual code reviews and penetration testing. - Mature Ibotta’s bug bounty program to scale with AI generated submissions and attack surface. - Analyze Ibotta's application architecture to identify weaknesses and develop opportunities for improvement. - Integrate and manage SAST, DAST, and SCA tools within the CI/CD pipeline. - Lead threat modeling for new application features with key stakeholders across mobile, platform, infrastructure and AI enablement. - Develop and maintain secure coding practices, provide training to developers. - Work with Ibotta’s engineering team to design, implement, and monitor runtime and container security controls across cloud platforms (AWS/GCP). - Automate infrastructure security checks using Infrastructure as Code (IaC) scanning tools. - Evaluate the security of AI-generated code and implement guardrails for model-serving endpoints in the development process. - Stay ahead of the curve on AI-specific threats such as prompt injection, data poisoning, and model inversion. - Participate in a 24/7

Free ATS check

Applying for this Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Ibotta?

Real rants from real employees. Read before you apply.

Read Company Rants →