Security Engineer II, Remote Job

Other Jobs To Apply

Who We Are

ActBlue is a nonprofit organization dedicated to creating cutting-edge technology that fuels Democratic victories and enables progressive causes to thrive.

Our vision is simple: building change through the power of people. Since our founding, we’ve been building innovative solutions to revolutionize grassroots fundraising – if you’ve donated to a Democratic campaign or a progressive organization online, you’ve probably used our platform! We believe in putting power in the hands of small-dollar donors by helping thousands of groups — from local candidates to national movements — mobilize their communities and create a lasting impact. Every member of our team is deeply committed to advancing our shared mission and core values. Together, we are shaping the future of democracy.

The Opportunity

The Security Team at ActBlue works to protect ActBlue from threat actors that might target ActBlue Technical Services (ATS), our donors, or the campaigns and organizations that fundraise on our platform. Our security program is anchored in empathy for our stakeholders, which is a primary value for our team.

Security Engineers work in concert with product engineering, platform, and operations engineers within engineering to perform security reviews early in their engineering process. The Security Engineer II will respond to incidents, detect threats across our tech stack, help perform ad hoc security reviews, and work on vulnerability triage.

What You Will Do

  • Maintain and enhance security related tooling with the team including Security Log Aggregation, AV, Development Buildtime and Cloud Runtime tooling

  • Automate detections throughout our tooling stack leveraged to uncover security events and attacks against our systems

  • Implement, iterate, and operate security automation aimed at supporting our engineers during their building processes, reducing the time it takes to remediate discovered vulnerabilities

  • Perform vulnerability assessments and ad hoc security reviews to identify and prioritize potential security risks and vulnerabilities

  • Partner closely with engineers to perform security reviews that support our software and infrastructure engineers early in their engineering process

  • Participate in incident response activities, including investigation, containment, and recovery efforts

What You Bring

  • You get git. You have a working level knowledge of how to manage with your local IDE and CLI, and routinely perform the activities of code committing

  • You’ll be asked to peer review code on the team and are familiar with typical +1 ceremonies

  • Experience in automating security workflows and functions for detections patterns utilizing AWS Lambda and Step Functions

  • Ability to deploy, manage, monitor, and/or provide sustainable operational support for a subset of technology that our team relies on to enforce security requirements and detect threat actors to defend ActBlue

  • You’ll have a deep understanding of modern TTPs used to target B2C online business

  • Ability to perform reviews that demonstrate deep domain expertise in one or more core security domains and secondary specializations (e.g., infrastructure security, application security, corporate IT security, security operations)

  • You will continuously readily learn and apply lessons learned from new attacks/attackers to your area of focus

  • Excellent communication skills

  • Experience with OWASP principles

  • Experience deploying tools that make it easier for engineers to build safely

  • Proficiency in Python, Ruby, and/or Go (Preference is ordered)

  • Ability to participate in the team’s on call rotation

What You’ll Be Working With

  • Dev stack: Ruby on Rails, React, PostgreSQL, Node.js, Redis

  • Infra stack: Amazon Web Services, K8s, Terraform

  • Business Systems: Gsuite, Okta, Github, Atlassian, Netsuite, Hubspot

Work & Benefits Snapshot

This posting is for a full-time, remote, salaried position. Travel may be required on a limited basis to attend all-staff and departmental retreats (1-2 times per year). Additional travel may be required for select positions.

Registered States: Arizona, California, Colorado, Connecticut, Florida, Georgia, Hawaii, Illinois, Maryland, Massachusetts, Michigan, Minnesota, Missouri, New Hampshire, New Jersey, New York, North Carolina, North Dakota, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Texas, Utah, Vermont, Virginia, Washington, Wisconsin, and Washington D.C.

While ActBlue is currently registered to support remote work in the states listed above, we possess the ability to register in additional states as needed. If you are located in a state not listed, we may still be able to proceed with your application, but please note that the offer process may take longer to accommodate registration requirements.

Work Schedule

This role requires availability during established, regular business hours (Mon-Fri) and is expected to be a part of an on-call rotation which will result in working nontraditional hours as needed.

Work Environment

Employees can expect to work with distributed teams across all U.S. time zones. Our roles require extended technology usage, and proficiency with virtual communication tools such as Zoom and Slack. Regular attendance in virtual meetings is inherent to every position.

Salary Range Details

Salary Range: $136,611 - $151,437 - $166,263

ActBlue is committed to consistent compensation practices across our organization. Final salary offers will take into account factors such as candidate experience, interview performance and current team salary parity.

Benefits

  • Flexible work schedules and an unlimited time-off policy

  • Fully paid and trans-inclusive health, dental, and vision insurance for employees and their families; plus fully-paid health reimbursement arrangement to use for out of pocket expenses and fully-paid short- and long-term disability

  • Fully paid basic and AD&D life insurance and a voluntary supplemental life insurance option

  • Dependent and health care flexible spending account options

  • Employee Assistance Program (EAP) benefits for employees

  • Automatic 2% Employer-paid 401K contribution, plus up to an additional 6% match on employee contributions

  • A minimum of three months paid medical, family and parental leave (for all new parents, adoptions included)

  • Commuter or home-office benefits, including a $1,000 home-office setup allowance for all new full-time remote employees

  • Additional perks including quarterly snack deliveries and digital subscriptions to the Boston Globe & New York Times

ActBlue is unable to sponsor work visas at this time.

Union Information

The terms and conditions of this position are subject to a collective bargaining agreement with the Communications Workers of America, the exclusive bargaining agent of covered ActBlue Technical Services employees.

Background Checks

As part of our hiring process, ActBlue will conduct a background check at the time of offer. This will be completed in compliance with applicable laws and will not be initiated without your consent.

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...