Staff Application Security Engineer

Cybersecurity Engineering

Team

Location

Virtual, Ontario

Department

Engineering

Job Type

Full Time

Thumbtack helps millions of people confidently care for their homes.

Thumbtack is the one app you need to take care of and improve your home — from personalized guidance to AI tools and a best-in-class hiring experience. Every day in every county of the U.S., people turn to Thumbtack to complete urgent repairs, seasonal maintenance, and bigger improvements. We help homeowners know projects to do, when to do them, and who to hire from our growing community of 300,000 local service businesses. If making an impact inspires you, join us. Imagine what we’ll build together.

An image of roofers working on a roofAn image of a family eating breakfast in their kitchen

About the Cybersecurity team

The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start.

We partner closely with Product, Engineering, Platform, and Data teams to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust.

Michelle - Engineering
Play button
Hear from
Michelle
https://res.cloudinary.com/dkhxbhhgg/video/upload/v1741030680/Engineering_Michelle_iagwpa.mp4
Senior Manager, Engineering
Michelle

 “Opinions from all across the organization are valued and listened to, and it’s easy and encouraged to get involved with a project you’re passionate about."

Michelle

Senior Manager, Engineering

 “Opinions from all across the organization are valued and listened to, and it’s easy and encouraged to get involved with a project you’re passionate about."

Michelle

Senior Manager, Engineering

The challenge

As Thumbtack scales and increasingly incorporates AI-powered features into our products and internal systems, security must evolve without slowing innovation. The number of services, deployment patterns, and data flows continues to grow, and traditional approaches that rely heavily on manual reviews or after-the-fact controls do not scale to meet this need.

Instead, The challenge is to design security into the system itself. This means building secure defaults, paved paths, and reusable building blocks that product and engineering teams can adopt with minimal friction. By embedding security directly into architectures, tooling, and infrastructure, we reduce cognitive load on engineers and enable teams to move quickly and confidently while meaningfully lowering risk.

What you'll do

  • Own the long-term technical direction for application security across Thumbtack. Build prioritized roadmaps and drive remediation of systemic security risks across the application stack.
  • Lead large, cross-functional security initiatives from problem definition through delivery.
  • Design secure-by-default architectures, standards, and paved paths for engineering teams. Design and implement shared security tooling, libraries, patterns, and services that enable engineering to ship quickly and safely. Embed security into CI/CD pipelines, cloud infrastructure, and developer workflows.
  • Partner with engineering and product leaders to prioritize security investments based on risk, impact, and business goals.
  • Lead application security design reviews, architectural discussions, and threat modeling for critical systems. Contribute code, reviews, and designs to address complex or novel security risks.
  • Mentor engineers and raise the overall security bar through guidance and example.
  • Support security incident response and drive learning through post-incident analysis.

In order to be successful, you must bring

  • 8+ years of experience in software engineering and application security, including a strong understanding of secure coding practices and application security frameworks.
  • Deep expertise in secure system design and architecture as well as modern application security tools, patterns, and practices (e.g. threat modeling, secure design patterns, authentication and authorization, secrets management, vulnerability discovery and remediation workflows).
  • Proven track record leading large, cross-functional technical initiatives with sustained impact.
  • Strong experience securing modern, cloud-native systems (AWS and/or GCP).
  • Strong product intuition and analytical, risk-informed thinking, identifying where security investments will have the highest leverage and measurable impact. Ability to balance pragmatism and rigor, making thoughtful tradeoffs between risk, velocity, and maintainability.
  • Strong sense of ownership and accountability, balancing hands-on technical execution with the ability to mentor others, raise standards, and drive organization-wide improvements in application security.
  • Excellent written and verbal communication skills, with the ability to influence without authority and the ability to explain complex security issues to both technical and non-technical audiences.

Expected salary ranges

  • For candidates living in Ontario and British Columbia, the expected salary range for the role is currently $221,000.00 - $286,000.00.

Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role.

Note: Thumbtack uses AI tools to support our resume screening process. However, our Recruiting team’s expertise and judgment guide hiring decisions.

Apply for this role

Thumbtack by the numbers

$600B+
opportunity in Thumbtack’s market home services
4.5M
customers in past 12 months
100M
projects started on Thumbtack
14M
5-star reviews
$3.2B
valuation (as of June 2021)

Scammers sometimes pose as Thumbtack recruiters or employees. Check out our blueprint on how to spot the fakes.

Apply for this role

Perks & Benefits

Supporting you at work and beyond

In addition to our virtual-first model, we offer:

Paid time off

Recharge with PTO, in addition to 20 company-wide holidays each year, including a week-long end-of-year shutdown.

Remote work stipend and reimbursements

$1,000 USD/$1,400 CAD annual stipend for professional development, self care, office set-up and more. We also provide cell phone and Wi-Fi reimbursements.

Support for parents and caregivers

All parents receive up to 12 weeks of paid parental leave, and birthing parents receive 8 additional weeks, for a total of 20 weeks of 100% paid parental leave (US & CAN).

Family formation benefits

$30,000 USD/CAD lifetime max reimbursement for family planning.

Mental health and financial coaching

12 coaching sessions and 12 therapy sessions for yourself and your dependents. We also offer one-on-one financial guidance from a financial wellness provider.

Thumbtack Bucks

$450 USD/CAD quarterly stipend to book a pro on Thumbtack for virtual or in-person services — anything from home care services to planning a child’s birthday party and beyond.

An image of employees working on a team building exercise at a recent Thumbtack eventAn image of employees doing yoga together

Perks & Benefits

Supporting you at work and beyond

In addition to our virtual-first model, we offer:

Paid time off

30 days of PTO (pro-rated based on start date), including a week-long, end-of-year shutdown and a 15% night shift differential.

Remote work stipend and internet allowance

PHP 46,600.00 annual stipend to use for professional development, self care, office set-up and more. We also provide PHP 1,500/month internet allowance.

Mental health and financial coaching

12 coaching sessions and 12 therapy sessions for yourself and your dependents. We also offer one-on-one financial guidance from a financial wellness provider.

Inclusive healthcare

HMO coverage includes yourself and up to three of your dependents (two at no cost). We also cover common-law and same-sex domestic partners.

An image of employees embracing after a team building exerciseAn image of employees at a recent Thumbtack event

Similar Roles

We found some other roles that might interest you

This role has been filled. Explore our job board for more openings.

Find your role