Smartsheet - Senior Software Engineer, Platform Security
Requirements
• 5+ years of progressive software development experience, with at least 3 years focused on building security features or secure applications, demonstrating sustained growth in technical depth and professional knowledge. • A Bachelor's or Master's degree in Computer Science, Engineering, or a related field, or equivalent industry experience providing the same level of knowledge and competency. • Expert-level proficiency in at least one major programming language such as Java, Kotlin, Go, or Python, with a proven history of building scalable and secure applications. • Deep experience with cloud technologies (AWS, Azure, etc.), particularly in securing cloud-native applications, and familiarity with the tools, platforms, and infrastructure involved in multi-cloud environments. • Experience developing, documenting, and supporting secure REST APIs, with attention to detail in both implementation and written technical documentation. • Strong understanding of common security vulnerabilities (e.g., OWASP Top 10) and mitigation techniques, with the ability to apply this knowledge independently and under pressure. • Experience with containerisation and orchestration technologies (Kubernetes) in a secure development context. • Proficiency with modern security tools and practices, including static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA). • Proven ability to troubleshoot complex security-related problems in high-pressure production environments, demonstrating critical thinking and sound independent judgement. • Excellent verbal and written communication skills in English, and a collaborative approach to working with cross-functional teams and stakeholders at all levels. • 1+ year of professional experience leveraging AI-based workflows to author, maintain, review, deploy, and maintain code. • 1+ year of experience building AI features that incorporate generative AI or agentic workflows to solve customer problems with measurable business impact. • Comfort working with ambiguity and shifting priorities in a fast-paced environment, with the psychosocial resilience to manage sustained cognitive effort and occasional incident-driven pressure. • No direct financial responsibility is associated with this role, though awareness of cost implications in architectural and tooling decisions is expected. • Ability to work independently in a remote setting within a psychologically safe and inclusive team environment, with standard flexible working hours aligned to the Bulgaria time zone and no travel requirements expected for this role. • Legal eligibility to work in Bulgaria on an ongoing basis. • Fluency in English is required. • Advanced industry certifications such as CSSLP, OSCP, or cloud-specific security certifications. • Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity. • Bulgaria Base Salary Pay Range€58,250 - €69,750 EUR • Get to Know Us: • Get to Know Us: • At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.
Responsibilities
• work remotely from Bulgaria. • Develop Secure Product Features: Design, build, and implement security features and functionalities directly into our SaaS product using modern programming languages (e.g., Java, Kotlin, Go, TypeScript, Python) and associated frameworks. • Develop Secure Product Features: • Build Scalable and Secure Services: Develop scalable back-end services and APIs with a security-first mindset, ensuring high availability and performance in our multi-cloud environment (primarily AWS). • Build Scalable and Secure Services: • Integrate Security into SDLC: Collaborate with product and engineering teams to embed security best practices throughout the entire software development lifecycle, from design to deployment. • Integrate Security into SDLC: • Automate Security Controls: Engineer and automate security controls, threat detection mechanisms, and vulnerability remediation processes within the application. • Automate Security Controls: • Conduct Code Reviews and Architectural Discussions: Participate actively in code reviews and architectural discussions, advocating for secure coding practices and robust security designs. • Conduct Code Reviews and Architectural Discussions: • Solve Challenging Security Problems: Tackle complex security challenges related to data protection, access control, authentication, authorization, and secure communication within a distributed system. • Solve Challenging Security Problems: • Create and maintain API integrations between internal and external systems. Implement and test API solutions to ensure they meet functionality, performance, and security standards. Monitor API performance and address any integration challenges or issues. • Create and maintain API integrations between internal and external systems. • Mentor and Lead: Serve as a subject matter expert in application security, mentoring junior engineers and fostering a culture of security ownership across development teams. • Mentor and Lead: • Strategically Apply AI Tools: Strategically apply and champion AI tools within your team's domain to improve project execution, system design, quality, and debugging, leading adoption of AI best practices and driving measurable productivity gains. • Strategically Apply AI Tools: • Assist with Security Incident Remediation: We manage a SOC on a global 24/7 basis. This role will assist in that effort during daytime working hours.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT