DoubleTap Consulting is a software consultancy that builds custom websites, product platforms and internal software for streaming, SaaS and commerce teams, working remotely from the United States with clients including Hulu, Auth0, Italic and Raven Health. We're hiring a Security Engineer to help protect the platforms and infrastructure we build and hand off to clients — work that's shipped as production code, not a slide deck, and owned outright by the teams we hand it to.
What you'll do
- Review application and infrastructure architecture for security risks across client engagements, from web platforms to internal tools and APIs
- Build and maintain secure coding standards, threat models and security review processes for engagements built on Next.js, React, React Native, Node and Postgres
- Set up and tune monitoring, logging and alerting so security issues are caught early and observable after handoff
- Conduct vulnerability assessments and coordinate remediation with engineering leads on each engagement
- Support secure design of authentication, payment and data-handling flows, including third-party integrations like Stripe Connect and identity platforms
- Document security posture and controls in a way client teams can own and run themselves once an engagement ends
What we're looking for
- Several years of experience in application security, infrastructure security, or a security-focused engineering role
- Solid understanding of common vulnerability classes (OWASP Top 10), secure coding practices, and cloud security fundamentals
- Hands-on experience with cloud infrastructure (AWS, GCP, or Azure) and infrastructure-as-code security review
- Experience securing modern web stacks — Node.js, React/Next.js or similar — and their supporting databases
- Comfortable working directly with engineers and clients rather than through a security or compliance layer
- Strong written communication skills, since findings and recommendations need to be understood by non-specialist client teams
Nice to have
- Experience with payment infrastructure security (e.g., Stripe Connect or similar)
- Familiarity with identity and access management platforms
- Background working in a consultancy or agency setting across multiple client codebases