09 Aug
|
atVenu
|
Calgary
Staff Developer / Development Manager, Application Security Reports To: Director of Development, Architecture Location: Calgary or Remote About the Job: When this company started, it was just a few of us furiously working to find product‑market fit, and as with many startups, technical debt accumulated. Ten years later, we've found that market fit. We're revenue positive, our customers love us, and with that growth has come new responsibility. PCI Level 1 became a requirement to do business, and we've achieved SOC 2 compliance — certifications we must maintain, along with our reputation and our commitment to our customers. While we have achieved a higher profile, an explosion of new penetration tools and techniques have emerged; we can no longer fly under the radar. While we work hard to improve our security, those efforts must be balanced against business and customer needs. We need people who can identify security concerns, prioritize them, and build solutions — all while understanding the ripple effects those changes will have across the business. While establishing a solid security posture, we want to proactively find and remediate issues before they are discovered for us and create a security‑first SDLC within the company. Our Tech Stack: Front End: React Native, React,
JavaScript Backend: Ruby on Rails, GraphQL, PostgreSQL, Redis, CouchDB Cloud Platform: AWS Tools: GitHub, Sidekiq, Docker What You’ll Do: Security at atVenu spans the codebase, the compliance program, and the team culture. You'll be part of all of it. Application security program leadership: Define the roadmap, own application security risks, and make the case to engineering and executive leadership for what gets resourced and when. You know when to accept calculated risk and when to hold the line — your decisions are pragmatic and reflect thought towards the needs of our business, our customers and compliance. Team management: Hire, develop, and retain application security developers. Set technical direction, run code and architecture reviews, unblock your team, and build a security culture that scales across a quick‑moving engineering organization without becoming a bottleneck. PCI, GDPR, and SOC2 ownership within the SDLC: Maintain and reduce cardholder data environment (CDE) scope across our Rails API, GraphQL layer, PostgreSQL, and mobile POS app. Own the SOC2 and PCI DSS controls within our software development lifecycle. Offline
📌 Staff Developer / Development Manager, Application Security (Calgary)
🏢 atVenu
📍 Calgary