CaptivateIQ is transforming the way companies plan, manage, and optimize sales
performance. We started by revolutionizing incentive compensation management,
and now we're expanding our platform to solve broader sales planning challenges.
Recognized by industry analysts like Forrester and G2 and backed by top-tier
investors, including Sequoia, ICONIQ and Accel, we empower high-growth companies
like Netflix, Figma and Stripe with the flexibility and insights needed to drive
revenue performance.
Join a talented, fast-growing team committed to solving some of the most complex
and impactful problems in sales performance management.
About the Role
Security is a core value at CaptivateIQ. As we scale and expand our suite of
services, embedding security into every phase of product development is critical
to building trust in everything we deliver.
As a Senior Security Engineer focused on Application & Product Security, you
will own our AppSec strategy - driving threat modeling, secure architecture
design, and offensive security testing. You will lead manual and automated
penetration testing, manage AppSec tooling (SAST, DAST, SCA), and build
developer enablement programs. You’ll also be responsible for vulnerability
management, incident response for application-layer events, and ensuring
compliance alignment for SOC 2, ISO 27001, and privacy requirements.
This role blends offensive and defensive expertise with strategic influence,
giving you the autonomy to shape a scalable, modern AppSec program.
Job Location
Remote
Raleigh, NC
Nashville, TN
Toronto, Canada
\n
Responsibilities
- Threat Modeling & Architecture Reviews Mature and scale a modern threat
modeling program across products and services. Enable secure by design
architectures in collaboration with Engineering teams.
- Offensive Security Testing Conduct penetration tests (white-box and
black-box) for web applications and APIs. Perform dynamic (DAST), static
(SAST), and software composition (SCA) analysis. Simulate adversary attack
scenarios to validate controls and identify gaps.
- Secure SDLC Integration Embed security into every stage of development;
implement automated security tooling in CI/CD pipelines.
- Vulnerability Management Triage and prioritize application-layer
vulnerabilities and guide engineering teams through remediation.
- Developer Enablement Deliver secure development and coding training; create
resources to reduce recurring vulnerabilities.
- Bug Bounty Management Oversee Bug Bounty program, validate findings, and
ensure timely resolution.
- Incident Response Leadership Lead investigations for application-layer
security incidents and conduct post-incident analysis.
- Compliance Enablement Support audits, technical evidence collection, and
control design for SOC 2, ISO 27001, and privacy-by-design requirements.
- Customer TrustContribute to customer security assessments, penetration test
reports, and security documentation.
Requirements
- 7+ years of experience in a security engineer or related role, including 4+
years specializing in web application, API, and product security.
- Deep expertise securing multi-tenant SaaS platforms and features.
- Strong communication and ability to influence software engineers and product
managers.
- Advanced experience conducting penetration tests, code reviews, and
vulnerability assessments.
- Expert knowledge of OWASP Top 10, web application and API security, and
common vulnerability classes with practical remediation strategies.
- Hands-on experience with AppSec tooling (SAST, DAST, SCA) integrated into
CI/CD pipelines.
- Strong programming and scripting skills (Python preferred) and ability to
influence secure coding practices.
- Proven ability to lead incident response for application-layer security
events.
- Familiarity with compliance frameworks (SOC 2, ISO 27001) and secure SDLC
practices.
- Knowledge of privacy-by-design principles and data security in SaaS
environments.
- Awareness of emerging AI/ML security risks and related countermeasures.
Nice to have
- Certifications such as OSCP, GCIH, GWAPT, or CISSP.
- Familiarity with security frameworks such as NIST CSF, MITRE ATT&CK, OWASP
ASVS, or ISO 27001.
- Experience with commercial security tools such as EDR, SIEM, CSPM, CNAPP,
vulnerability scanners, bug bounty platforms, WAFs, or compliance automation
platforms.
- Prior experience driving security engineering for a SaaS-based company.
- Experience leveraging automation or AI/ML tools to improve secure
development, detection, incident response, or code analysis workflows.
Benefits
- (US-ONLY) 100% of medical, dental, and vision covered including 75% for
dependents
- Flexible vacation days and quarterly mental health days so you can recharge
- Enjoy a one-time expense on your 1-year work anniversary (to use for travel,
home furnishings, fancy meal)
- (US-ONLY) 401k plan to participate in and save towards the future
- Newest Apple products to help you do your best work
- Employee Resource Groups (ERGs) to support and celebrate the shared
identities and life experiences of communities within CaptivateIQ. ERGs
directly support our company-wide DEI goals as a space for developing and
retaining diverse talent
Notice to Prospective Candidates
- Only emails from @captivateiq.com should be trusted.
- We are aware of active recruitment scams using the CaptivateIQ name, in which
individuals pose as our recruiters and post fake remote job openings and make
fake job offers on the Internet. Please note, we will never do the following:
- Attempt to correspond with a candidate using a free web-based account, such
as an email address that ends in @gmail.com, @yahoo.com, @hotmail.com, etc.
- Make an offer of employment without conducting multiple rounds of interviews
face-to-face using secure video-conferencing technology.
- Ask candidates to cash checks to buy equipment on behalf of CaptivateIQ.
- Ask candidates to make a payment in order to be considered for a position.
- Make early requests for candidates' personal information such as date of
birth, passport details, credit card numbers, bank details and social
security number, etc.
- Please note that we’ll only ask for more sensitive personal information in
connection with background checks after an offer is made.
- Participate in an on-call rotation to provide after-hours support, ensuring
timely resolution of critical issues and maintaining system uptime.
\n
$154,500 - $197,760 a year
The base range represents the minimum and maximum for this position across North
America. For candidates in Raleigh , the range is $170,980–$197,760; for
Toronto, and Nashville locations, the range is $154,500–$177,160. The
compensation offered for this position will depend on numerous factors,
including individual proficiency, anticipated performance, and the location of
the selected candidate. Our OTE is just one component of CaptivateIQ's
competitive total rewards package.
\n
CaptivateIQ participates in E-Verify, web-based system that allows enrolled
employers to confirm the eligibility of their employees to work in the United
States