More jobs:
Senior Security Engineer
Job in
Redwood City, San Mateo County, California, 94061, USA
Listed on 2026-01-01
Listing for:
Box
Full Time
position Listed on 2026-01-01
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer
Job Description & How to Apply Below
BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI‑first era of business. Founded in 2005, Box simplifies work for leading global organizations, including JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.
By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations.
With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.
WHY BOX NEEDS YOU
Box is building the industry’s most trusted, secure content and AI platform. Our Security Assurance Engineering team (part of Platform Security) is looking for a Senior Security Engineer who possesses an adversarial mindset and partners with engineering, product management and other security teams to find and fix product and platform vulnerabilities across web, mobile, APIs, microservices, and other surfaces. You will help ensure Box remains secure‑by‑design and secure‑by‑default while enabling rapid, responsible product development and AI adoption.
WHAT YOU'LL DO
• Lead and execute hands‑on, technical security assessments at the product and feature level: manual code reviews, design reviews, threat models, web & mobile penetration tests, fuzz testing, and vulnerability risk analysis.
• Discover and validate vulnerabilities (front‑end, APIs, microservices, containers), determine exploitability and business impact, and recommend mitigation and secure architecture changes.
• Secure how Box builds AI products and use AI to make Box products more secure.
• Build capabilities, modules and mechanisms to eliminate classes of vulnerabilities from Box products and platforms.
• Produce clear, technical reports and remediation guidance for engineering teams; communicate risk and proposed solutions to technical and non‑technical stakeholders.
• Drive and maintain secure coding requirements, secure design patterns, and bug bars; embed requirements into patterns, platforms, and CI/CD/SAST/DAST workflows.
• Support and triage submissions for Bug Bounty and VDP programs; coordinate PSIRT handoffs for fixes and incident tracking.
• Support engineers and security champions; collaborate with Product, Engineering, Security Architecture, Production Security, and Platform Security Tools & Engineering to scale detection and remediation.
• Participate in our on‑call rotation, available at all times while on‑call to help respond to and triage any issues that arise.
WHO YOU ARE
We are an AI‑first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.
• 5+ years hands‑on experience performing end‑to‑end security assessments: threat modeling, secure code review, and manual penetration testing across web/mobile/API environments.
• Strong offensive skills: manual pen testing, exploitation reasoning, fuzzing, use of tools like Burp Suite; experience with DAST/SAST/fuzz pipelines a plus.
• Deep practical experience with at least one of:
Java, React/JS/Type Script, Node.js, Python, PHP, Scala, C/C++, Go.
• Demonstrated ability to find and assess vulnerabilities across front‑end, APIs, microservices and mobile applications; understand supply‑chain risk and OSS component management.
• Excellent vulnerability risk analysis skills: determine severity, exploitability, and business impact; create concise remediation plans…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×