Security Engineer

Ibotta·Ashby
RemotePosted Jun 28, 2026
Open original posting
Security Engineer LocationHybrid - DenverEmployment TypeFull timeLocation TypeOn-siteDepartmentTechnical - Non-EngineeringIbotta is seeking a Security Engineer with a deep expertise in Application Security, Vulnerability Management, and Cloud Infrastructure to join our innovative team and contribute to our mission to Make Every Purchase Rewarding. In this role, you will be ensuring the security of our software development lifecycle (SDLC) and our cloud-native environments. A key focus of this position will be addressing the emerging security challenges posed by Artificial Intelligence (AI) technologies, specifically around secure AI coding practices and the infrastructure that supports AI/ML workloads. This position is located in Denver, Colorado as a hybrid position requiring 3 days in office (Tuesday, Wednesday, and Thursday). Candidates must live in the United States. Not based in Denver? We will offer a relocation bonus to help make your move to the Mile High City a smooth one. What you will be doing:Perform application security assessments, including manual code reviews and penetration testing.Mature Ibotta’s bug bounty program to scale with AI generated submissions and attack surface.Analyze Ibotta's application architecture to identify weaknesses and develop opportunities for improvement.Integrate and manage SAST, DAST, and SCA tools within the CI/CD pipeline.Lead threat modeling for new application features with key stakeholders across mobile, platform, infrastructure and AI enablement.Develop and maintain secure coding practices, provide training to developers.Work with Ibotta’s engineering team to design, implement, and monitor runtime and container security controls across cloud platforms (AWS/GCP).Automate infrastructure security checks using Infrastructure as Code (IaC) scanning tools.Evaluate the security of AI-generated code and implement guardrails for model-serving endpoints in the development process.Stay ahead of the curve on AI-specific threats such as prompt injection, data poisoning, and model inversion.Participate in a 24/7 on-call rotation and incident response.Embrace and uphold Ibotta’s Core Values: Integrity, Boldness, Ownership, Teamwork, Transparency & A Good Idea Can Come from Anywhere  What we are looking for:4+ years in security engineering, application development, or application security.Proficiency in languages like Python, Go, or Java; experience with Docker/Kubernetes.Basic knowledge of networking security is a plus.Strong knowledge of AWS security services and IaC (Terraform). Experience writing secure IAM policies and other configurations in Terraform a plus.Understanding of Continuous Integrations/Testing/DeliveryStrong understanding of Web API security patterns and modern authentication protocols.Familiarity with OWASP Top 10 and implementing technical controls to address vulnerabilities.Working knowledge of web application testing tools.One or some combination of the following are a plus but not required: CompTIA SecAI+, eCPPT, eWPT, GWAPT, OSCP, or similar.Must have the ability to work effectively across the organization/collaborate effectively with both technical and non-technical team members, possess excellent oral & written communications skills, and demonstrate effective problem-solving skills.Experience building custom security tooling or automation scripts.   About Ibotta ("I bought a...") Ibotta (NYSE: IBTA) is a leading performance marketing platform allowing brands to deliver digital promotions to over 200 million consumers through a network of publishers called the Ibotta Performance Network (IPN). The IPN allows marketers to influence what people buy, and where and how often they shop – all while paying only when their campaigns directly result in a sale. American shoppers have earned over $2.6 billion through the IPN since 2012. The largest tech IPO in history to come out of Colorado, Ibotta is headquartered in Denver, and is continually listed as a top place to work by...

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free