Location: Denver, CO, USA ONSITE   |   Full-Time
Security Application Security AppSec Authentication Authorization OAuth SAML OIDC Threat Modeling Vulnerability Assessment Penetration Testing Java Docker Kubernetes Cloud Security Onsite Security Engineer Back End Engineer
FusionAuth is hiring a Senior Security Engineer for an ONSITE role based in Denver, CO. Our core mission is to make authentication and authorization simple and secure for developers building web and mobile applications.

**About FusionAuth:**
We provide a flexible authentication platform deployed globally, offering self-hosting, private cloud, and SaaS options. Our API-first product is mature yet actively developed. We are founder-led, profitable, and backed by a recent $65M investment to accelerate our growth. We build high-quality software focusing on developer needs and robust security. We utilize technologies like Java, MySQL, PostgreSQL, Docker, and Kubernetes and implement standards like OAuth, SAML, and OIDC.

**Role & Responsibilities:**
As a Senior Security Engineer, you will be a key part of ensuring the security and integrity of the FusionAuth platform and company operations. Your responsibilities will span application security, infrastructure security, and compliance. This includes:
*   Conducting security architecture reviews and threat modeling for new and existing features.
*   Performing vulnerability assessments and managing penetration testing efforts.
*   Developing and implementing security features within the FusionAuth product.
*   Contributing to security best practices, tooling, and automation.
*   Responding to security incidents and coordinating remediation efforts.
*   Staying abreast of emerging security threats and technologies in the identity and access management space.

**Technical Skills Required:**
*   Deep understanding of application security principles and common vulnerabilities (OWASP Top 10).
*   Experience securing web applications and APIs, particularly in a Java ecosystem.
*   Knowledge of authentication and authorization protocols (OAuth, OIDC, SAML).
*   Familiarity with cloud security concepts and technologies (Docker, Kubernetes, AWS/GCP/Azure).
*   Experience with security assessment tools and techniques.
*   Scripting or programming skills for automation (e.g., Python, Java).

**Ideal Candidate:**
You have a strong background in software or application security and are passionate about protecting systems and data. You possess a proactive mindset towards identifying and mitigating risks. You can communicate complex security concepts effectively to technical and non-technical audiences. You are comfortable working in a dynamic environment and contributing to a security-first culture. This is an ONSITE role in Denver, CO.
Post Date: April 21, 2025