bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesVerygoodsecurityApplication Security Intern

Application Security Intern

Verygoodsecurity · United States · Remote · Active · $20–$20 / hour · Lever

Job facts

FieldValue
CompanyVerygoodsecurity
TitleApplication Security Intern
Normalized title-
Department / teamR&D / Security & Compliance
LocationUnited States
Work modelRemote / Remote
Employment typeIntern
Salary$20–$20 / hour
Statusactive
ATS providerLever
Posted / first seen2026-04-16 / 2026-05-29
Changed / last seen2026-06-06 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Verygoodsecurity.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Lever.Open
Provider filtered searchThe same provider as a filtered job collection.Open
Department jobsActive postings in R&D.Open
Work model jobsActive Remote postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyVerygoodsecurity
Source03983f17-603c-4cc7-8a20-b97859bfcb62
ATS providerLever

Description

VGS is the world's leader in payment tokenization. Large banks, aspiring fintechs, and growing merchants embed our universal token vault into their technology stack to manage the complexities of payment data tokenization across processors and networks, open banking, card issuance, omnichannel loyalty, PCI compliance, payment orchestration, and more. We empower our clients and partners by tokenizing sensitive payment data, limiting compliance scope, and consolidating payments to unlock revenue and business opportunities. VGS provides processor-agnostic tokenization solutions via secure universal token vaults, iframes, mobile SDKs, tokenization proxies, APIs, and data orchestration tooling to support payment acceptance, card issuance, PII and bank account tokenization, and other payments value-added services. Some of the use cases we enable include multi-processor Network Tokenization, Account Updater, payment orchestration, secure settlement file processing, 3DS, and Risk provider connectivity. We are looking for a curious, motivated Application Security Intern to help us build secure products and development practices at VGS. In this role, you will partner with security and engineering teams to evaluate application risk, improve secure software development workflows, and help developers ship software safely in an environment that handles highly sensitive payment and identity data. You will likely be successful in this role if you identify with the following traits: attention to detail, problem solver, customer-oriented, versatile, resilient, and eager to learn. If all of this sounds interesting to you, we’d love to hear from you. At VGS, we have a remote-first philosophy because we believe flexibility leads to great work and a healthy work-life balance. That said, if you live within 30 miles of one of our office locations, you’ll be on a hybrid schedule with some in-person time, because we know there’s real value in coming together. We’re not about being in the office every day, but we are about connection, collaboration, and the energy that comes from a great brainstorm, a team lunch, or celebrating a big win in person. We consider applicants without regard to race, color, national origin, sex, age, religion, sexual orientation, gender identity, veteran status, marital status, physical or mental disability, or other protected classes under all local, state, and federal laws and ordinances (AA/EOE/W/M/Vet/Disabled). Qualified applicants with arrest and conviction records will be considered for the position in accordance with the San Francisco Fair Chance Ordinance. Visa Sponsorship. The Company does not provide visa sponsorship for this role. Candidates must be legally authorized to work in the United States at the time of hire and throughout their employment. Individuals with temporary visas such as E, F-1 (including those with OPT or CPT), H-1, H-2, L-1, B, J, or TN, or who need sponsorship for work authorization now or in the future, are not eligible. Please note we are currently only hiring in the following states... California, Colorado, Connecticut, Florida, Illinois, New York, North Carolina, Oregon, Texas, Virginia, and Washington What you will be doing at VGS… Support application security reviews for services, APIs, and new product features across the VGS platform. Help identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools. Participate in threat modeling and secure design discussions with engineering teams during feature development. Help evaluate the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC, by thinking like both an attacker and a defender to identify risks and improve guardrails. Assist with manual testing and validation of web application and API security issues, including access control, authentication, input validation, and secrets handling. Help improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists. Work with engineers to understand remediation options and clearly document security risks and recommendations. Contribute to improving security tooling and guardrails in CI/CD and development workflows. Be proactive and innovative; we rely on your feedback to help build a world-class product securely. Be a part of a team that believes in transparency, collaboration, grit, and humility, and in doing the right thing for our customers and the company. What we are looking for from you (Requirements)… Currently pursuing a degree in Computer Science, Cybersecurity, Software Engineering, or a related field, or have equivalent practical experience. Foundational understanding of application security concepts such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities. Ability to read and reason about code in one or more programming languages such as Java, Python, JavaScript, or Go. Familiarity with Git, the software development lifecycle, and basic testing or debugging workflows. Strong interest in secure software design, cloud-native architectures, and automation. Strong written and verbal communication skills, with the ability to explain technical issues clearly to both security and engineering stakeholders. Curious, collaborative, and excited to learn how security can enable developers rather than slow them down. Participate in team-based on-call rotations to maintain system reliability, actively responding to incidents, troubleshooting production issues, and conducting root cause analysis to drive long-term service improvements. Bonus points if you have exposure to LLMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, or cloud environments.

Full job record

Job ID54ed89879b481222f22c1b181b560edad4dd4bf7
Org ID47bb39d2-4f34-4479-bd8f-ecfcfe744003
Source ID03983f17-603c-4cc7-8a20-b97859bfcb62
Board ID03983f17-603c-4cc7-8a20-b97859bfcb62
Providerlever
Provider Job Key32fe92a6-13d5-4132-b77c-a7a5ed74f38b
TitleApplication Security Intern
Normalized Title
Statusactive
Activeyes
Location TextUnited States
DepartmentR&D
TeamSecurity & Compliance
Employment TypeIntern
Workplace Typeremote
Remote Policyremote
CountryUnited States
Region
City
Salary RawUSD 20-20 per-hour-wage
Salary Min20
Salary Max20
Salary CurrencyUSD
Salary Periodhour
Source URLhttps://jobs.lever.co/verygoodsecurity/32fe92a6-13d5-4132-b77c-a7a5ed74f38b
Apply URLhttps://jobs.lever.co/verygoodsecurity/32fe92a6-13d5-4132-b77c-a7a5ed74f38b/apply
First Seen At2026-05-29 07:11:51Z
Last Seen At2026-06-06 18:48:10Z
Last Checked At2026-06-06 18:48:10Z
Last Changed At2026-06-06 07:54:57Z
Inactive At
Source Posted At2026-04-16 17:30:09Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=lever/board=verygoodsecurity/date=2026-06-06/2026-06-06T18-48-09-737Z-195202d7d908728c960d1d80dd5905d296c83c0136a52ea83501bdd924c2dd6b.json
Event Fields
{
  "content_hash": "02bfa8cc3490f2bef8433ae69dff2d51cc7af2a8272a650c092e4bb57f8f293d",
  "source_hash": "0183543091b9e49403706522b8ff31fd545ab609081397c28a84f07b93bca76a",
  "last_changed_at": "2026-06-06T07:54:57.165Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "United States",
    "city": null,
    "region": null,
    "country": "United States",
    "is_remote": true,
    "confidence": 0.95
  },
  "salary_max": 20,
  "salary_min": 20,
  "inferred_at": "2026-06-06T18:48:10.256Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "United States",
      "city": null,
      "region": null,
      "country": "United States",
      "is_remote": true,
      "confidence": 0.95
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "remote",
  "salary_period": "hour",
  "workplace_type": "remote",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "lists": [
    {
      "text": "What you will be doing at VGS…",
      "content": "<div>\n\n<li>\n<p>Support application security reviews for services, APIs, and new product features across the VGS platform.</p>\n</li>\n<li>\n<p>Help identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools.</p>\n</li>\n<li>\n<p>Participate in threat modeling and secure design discussions with engineering teams during feature development.</p>\n</li>\n<li>\n<p>Help evaluate the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC, by thinking like both an attacker and a defender to identify risks and improve guardrails.</p>\n</li>\n<li>\n<p>Assist with manual testing and validation of web application and API security issues, including access control, authentication, input validation, and secrets handling.</p>\n</li>\n<li>\n<p>Help improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists.</p>\n</li>\n<li>\n<p>Work with engineers to understand remediation options and clearly document security risks and recommendations.</p>\n</li>\n<li>\n<p>Contribute to improving security tooling and guardrails in CI/CD and development workflows.</p>\n</li>\n<li>\n<p>Be proactive and innovative; we rely on your feedback to help build a world-class product securely.</p>\n</li>\n<li>\n<p>Be a part of a team that believes in transparency, collaboration, grit, and humility, and in doing the right thing for our customers and the company.</p>\n</li>\n\n</div>"
    },
    {
      "text": "What we are looking for from you (Requirements)…",
      "content": "<div>\n\n<li>\n<p>Currently pursuing a degree in Computer Science, Cybersecurity, Software Engineering, or a related field, or have equivalent practical experience.</p>\n</li>\n<li>\n<p>Foundational understanding of application security concepts such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities.</p>\n</li>\n<li>\n<p>Ability to read and reason about code in one or more programming languages such as Java, Python, JavaScript, or Go.</p>\n</li>\n<li>\n<p>Familiarity with Git, the software development lifecycle, and basic testing or debugging workflows.</p>\n</li>\n<li>\n<p>Strong interest in secure software design, cloud-native architectures, and automation.</p>\n</li>\n<li>\n<p>Strong written and verbal communication skills, with the ability to explain technical issues clearly to both security and engineering stakeholders.</p>\n</li>\n<li>\n<p>Curious, collaborative, and excited to learn how security can enable developers rather than slow them down.</p>\n</li>\n<li>Participate in team-based on-call rotations to maintain system reliability, actively responding to incidents, troubleshooting production issues, and conducting root cause analysis to drive long-term service improvements.</li>\n<li>\n<p>Bonus points if you have exposure to LLMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, or cloud environments.</p>\n</li>\n\n</div>"
    }
  ],
  "country": "US",
  "createdAt": 1776360609723,
  "updatedAt": null,
  "categories": {
    "team": "Security & Compliance",
    "location": "United States",
    "commitment": "Intern",
    "department": "R&D",
    "allLocations": [
      "United States"
    ]
  },
  "salaryRange": {
    "max": 20,
    "min": 20,
    "currency": "USD",
    "interval": "per-hour-wage"
  },
  "workplaceType": "remote"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/54ed89879b481222f22c1b181b560edad4dd4bf7?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/47bb39d2-4f34-4479-bd8f-ecfcfe744003JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/03983f17-603c-4cc7-8a20-b97859bfcb62JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/54ed89879b481222f22c1b181b560edad4dd4bf7/eventsJSON