Senior DevSecOps / Security Engineer – Application & Cloud (Ecommerce)

Remote Full-time
Description

At Thorne, we work to deliver high-quality, science-backed solutions to empower individuals to take a proactive approach to their well-being. Each day begins with a mission to help others discover and achieve their best health. We count on our team members to challenge and push the boundaries to make that happen. At Thorne, you’ll be joining a team of more than 750 passionate individuals committed to our cause of providing superior health solutions at every age and life stage.

Thorne is seeking a Senior DevSecOps / Security Engineer – Application & Cloud (Ecommerce) to secure and scale our digital platforms, including Thorne.com, mobile applications, and emerging AI capabilities. This role sits at the intersection of application security, DevSecOps, and AWS cloud infrastructure, with a strong focus on protecting ecommerce systems, customer data, and high-traffic web applications. The ideal candidate will balance remediations and hands-on execution, ensuring systems are resilient, performant, and secure, while embedding security throughout the development lifecycle.

RESPONSIBILITIES

Application & Ecommerce Security
• Identify and remediate vulnerabilities in Java-based applications (Spring Boot, APIs, microservices)
• Address OWASP Top 10 and ecommerce-specific risks, including:

o Injection (SQL/NoSQL), XSS, CSRF

o Broken authentication / session management

o Business logic flaws (checkout, pricing, promotions, abuse scenarios)

o Account takeover, credential stuffing, bot attacks
• Secure checkout flows, payment integrations, subscriptions, and customer data handling
• Conduct secure code reviews and support threat modeling for new features

API & Integration Security
• Secure REST/GraphQL APIs (authentication, authorization, rate limiting)
• Prevent API abuse, scraping, and data exfiltration
• Implement and enforce secure patterns (OAuth2, JWT, token management)

DevSecOps & CI/CD Security
• Implement and manage security tooling in CI/CD pipelines:

o SAST (Java-focused), DAST, SCA (dependencies), secrets scanning
• Secure build and deployment pipelines
• Enforce secure coding standards and automate policy checks
• Own infrastructure-as-code security (Terraform) for app environments

AWS Cloud Security (Critical)
• Secure application workloads on AWS (EKS/ECS, EC2, Lambda, API Gateway, S3, RDS)
• Implement and validate:

o IAM roles and least privilege access

o Network segmentation (VPCs, security groups, private/public boundaries)

o Secrets management (AWS Secrets Manager, Parameter Store)

o Data protection (encryption at rest/in transit)
• Partner with Infra to ensure alignment with enterprise guardrails, while owning app-layer cloud security

Runtime Protection & Detection
• Implement and tune WAF, bot protection, and rate limiting for ecommerce surfaces
• Partner with Infra on CrowdStrike coverage for application workloads
• Support detection and response improvements for:

o Web/app-layer attacks

o API abuse
• Triage and remediate findings from:

o Pen tests

o Purple team exercises

o Assumed breach scenarios

Security Program Execution
• Translate security findings into prioritized engineering work
• Partner with external security testing partners on risk prioritization (CTRM) tied to business impact
• Drive adoption of security best practices across engineering teams
• Act as a bridge between Ecom, Infrastructure, and external security partners

WHAT YOU NEED

Application & Ecommerce Security
• Identify and remediate vulnerabilities in Java-based applications (Spring Boot, APIs, microservices)
• Address OWASP Top 10 and ecommerce-specific risks, including:
• Injection (SQL/NoSQL), XSS, CSRF
• Broken authentication / session management
• Business logic flaws (checkout, pricing, promotions, abuse scenarios)
• Account takeover, credential stuffing, bot attacks
• Secure checkout flows, payment integrations, subscriptions, and customer data handling
• Conduct secure code reviews and support threat modeling for new features

API & Integration Security
• Secure REST/GraphQL APIs (authentication, authorization, rate limiting)
• Prevent API abuse, scraping, and data exfiltration
• Implement and enforce secure patterns (OAuth2, JWT, token management)

DevSecOps & CI/CD Security
• Implement and manage security tooling in CI/CD pipelines:
• SAST (Java-focused), DAST, SCA (dependencies), secrets scanning
• Secure build and deployment pipelines
• Enforce secure coding standards and automate policy checks
• Own infrastructure-as-code security (Terraform) for app environments

AWS Cloud Security (Critical)
• Secure application workloads on AWS (EKS/ECS, EC2, Lambda, API Gateway, S3, RDS)
• Implement and validate:
• IAM roles and least privilege access
• Network segmentation (VPCs, security groups, private/public boundaries)
• Secrets management (AWS Secrets Manager, Parameter Store)
• Data protection (encryption at rest/in transit)
• Partner with Infra to ensure alignment with enterprise guardrails, while owning app-layer cloud security

Runtime Protection & Detection
• Implement and tune WAF, bot protection, and rate limiting for ecommerce surfaces
• Partner with Infra on CrowdStrike coverage for application workloads
• Support detection and response improvements for:
• Web/app-layer attacks
• API abuse
• Triage and remediate findings from:
• Pen tests
• Purple team exercises
• Assumed breach scenarios

Security Program Execution
• Translate security findings into prioritized engineering work
• Partner with external security testing partners on risk prioritization (CTRM) tied to business impact
• Drive adoption of security best practices across engineering teams
• Act as a bridge between Ecom, Infrastructure, and external security partners

WHAT WE OFFER
• Competitive compensation
• 100% company-paid medical, dental, and vision insurance coverage for employees
• Company-paid short- and long-term disability insurance
• Company- paid life insurance
• 401k plan with employer matching contributions up to 4%
• Gym membership reimbursement
• Monthly allowance of Thorne supplements
• Paid time off, volunteer time off and holiday leave
• Training, professional development, and career growth opportunities

About Thorne

We specialize in delivering innovative solutions and exceptional services to meet the diverse needs of our clients. With a strong commitment to quality and customer satisfaction, we strive to exceed expectations and drive success in every project we undertake.

Thorne is the leader in science-backed health and wellness solutions committed to helping individuals live healthier longer. As the top recommended clinical brand by healthcare practitioners, Thorne offers a comprehensive range of products including nutritional supplements and health tests designed to meet the unique needs of individuals at every stage of life. Founded in 1984, Thorne products are formulated with the highest-quality ingredients, supported by clinical research, and rigorously tested to ensure purity, potency, and efficacy. Thorne is trusted by 47,000+ health-care professionals, thousands of professional athletes, more than 100 professional sports teams, multiple U.S. National Teams, and more than five million consumers. For more information, visit Thorne.com.

THORNE IS AN EQUAL OPPORTUNITY EMPLOYER

Apply tot his job

Apply To this Job
Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Utilization Management Nurse Consultant – Behavioral Health (Remote)

Remote

Inside Sales Manager (Remote in Phoenix)

Remote

Windchill Java Customization Engineer

Remote

Data Entry Clerk – Work From Home | Online Typing & Part-Time Jobs

Remote

Network Engineer (m/f/d)

Remote

Experienced Part-Time Data Entry Specialist – Remote Work Opportunity for Detail-Oriented Professionals at arenaflex

Remote

Remote Security Specialist jobs Jobs in West Des Moines, Iowa | Remote Work From Home

Remote

Experienced Remote Customer Service Representative – Insurance Support and Policy Management

Remote

Remote Legal Compliance Advisor

Remote

Urgently Require Math Teacher/Tutor in Carlsbad, CA

Remote
← Back