Senior Security Engineer
Listed on 2026-08-22
-
Security
Cybersecurity, Information Security & Data Protection
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Senior Security EngineerFull Time Augusta, GA, US
Senior Security Engineer
- Product Security
Augusta, Ga
Work Location & ScheduleThis is a hybrid position based in our Augusta, GA office
. Team members are expected to work on-site two days per week in our Augusta office and
remotely three days per week
. This schedule supports collaboration while offering flexibility and work-life balance.
For the right candidate, this position may also be considered as a fully remote opportunity for individuals residing in Georgia, South Carolina, North Carolina, Florida, or Tennessee only.
At Tax Slayer, we're more than just a tax software development company; we’re empowering individuals and small businesses to plan for and file their tax returns online with confidence and ease. As a leading innovator in tax prep software, Tax Slayer, LLC, has been revolutionizing the way people file their taxes since 1965. Our user-friendly platform offers an intuitive interface that guides customers through the tax-filing process step by step, ensuring accuracy and maximum refunds.
Tax Slayer is headquartered in Augusta, GA with a satellite office in Charlotte, NC. Tax Slayer proudly employs nearly 200 individuals year-round, plus 300 additional in-season support agents. Our employees are among the brightest, most talented group of innovators who work collaboratively to improve our products and exceed customer expectations season after season.
About the RoleThe Senior Security Engineer – Product Security serves as the primary security partner to software development teams, helping ensure security is embedded throughout the software development lifecycle. This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing Tax Slayer's bug bounty program, and supporting compliance and risk management initiatives. Working closely with engineering, product, and Information Security teams, this position helps protect sensitive taxpayer and financial data while fostering secure development practices across the organization.
CoreResponsibilities
- Serve as the primary security point of contact for assigned Development teams, participating in sprint planning, architecture discussions, and design reviews.
- Review product features, system designs, APIs, authentication mechanisms, and third-party integrations to identify and mitigate security risks.
- Partner with engineering teams to integrate security controls early in the software development lifecycle and promote secure coding practices.
- Conduct secure code reviews, threat modeling activities, architecture risk assessments, and security testing for applications and product releases.
- Perform hands-on penetration testing and coordinate third-party testing efforts when appropriate.
- Manage and optimize SAST, DAST, and CI/CD security tooling and processes.
- Track identified vulnerabilities through remediation and collaborate with engineering teams to address findings.
- Own day-to-day administration of the company's bug bounty program, including researcher engagement, submission triage, validation, and remediation coordination.
- Monitor and report bug bounty program performance metrics and recommend process improvements.
- Support governance, risk, and compliance initiatives, including audits and assessments related to PCI DSS, SOC 2, IRS security requirements, and other applicable regulations.
- Contribute to enterprise risk management activities and maintain product-level security risk documentation.
- Assist with security incident response activities, including investigation, root cause analysis, and remediation tracking.
- Mentor engineering teams on secure coding practices, threat modeling, and product security best practices.
- Other duties as assigned.
- Reduction in application and product security vulnerabilities identified in production environments.
- Timely completion of security reviews, threat models, and vulnerability remediation activities.
- Effective integration…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).