Build and operate an agentic application security program using AI for automated testing, triage, and PR review. Drive end-to-end vulnerability remediation, eliminate vulnerability classes via code changes, and lead threat modeling for a fintech platform handling sensitive financial data. Requires 4+ years appsec experience, hands-on tooling expertise, enthusiasm for LLMs, and Python engineering skills.
170k – 200k/yr
Hybrid4+ YOESecurity Engineering
About the role
What you'll do
Build and operate an agentic application security program: integrate SAST, DAST, and SCA into CI/CD, use LLM-based triage to reduce noise, and implement automated security review of pull requests for fast feedback.
Drive vulnerability remediation end-to-end: triage findings from scanners, penetration tests, and researchers; route fixes to teams; track to closure against SLAs; and verify fixes.
Eliminate vulnerability classes at the root by shipping secure defaults, paved-path libraries, and framework-level fixes through targeted code changes in the product codebase.
Lead threat modeling and security review for new features, engaging early with product engineers; automate the practice so threat models are living documents drafted by agents.
Tune and evolve the program's signal quality with new rules, better prompts, and fewer false positives, treating the agentic pipeline as an iterated product.
Stay current on vulnerabilities relevant to a fintech platform handling financial and tax data and translate insights into program changes.
What you'll bring
4+ years of security engineering experience with deep application security knowledge of major vulnerability classes (introduction, exploitation, durable fixes) and improving production platform security posture.
Hands-on experience with SAST, DAST, and SCA tooling (Semgrep, CodeQL, Bandit, OWASP ZAP, Burp Suite or equivalents) and CI/CD integration, plus judgment on which findings matter.
Genuine enthusiasm for building with LLMs and AI agents: experience using them to automate security work, writing/evaluating prompts and workflows for reliable agentic tooling.
Sufficient software engineering skills to make confident changes in a production codebase (Python/Django on AWS), including reading unfamiliar code, shipping libraries, and fixing vulnerability patterns across services.
Experience driving remediation through un-managed teams with clear writeups, defensible severity calls, and persistence without damaging relationships.
Product empathy to shape security feedback that engineers act on, optimizing for fixed vulnerabilities.
Security Engineer responsible for endpoint security architecture, MDM administration (Jamf, Intune), compliance enforcement, and automation across macOS, Windows, iOS, and Android devices. Requires 3-6 years MDM experience, OSQuery/CrowdStrike expertise, and a security-first mindset.
170k – 205k/yr
On-site3+ YOESecurity Engineering
Software Engineer, Trust & Safety
SunoSan Francisco, CA
Suno is seeking a Software Engineer, Trust & Safety to protect its platform and users from abuse, fraud, and harmful content. This role involves building data pipelines, anomaly detection systems, and internal tools to ensure user safety and platform integrity.
170k – 240k/yr
On-site3+ YOESecurity Engineering
Vulnerability Automation Engineer
Lumin DigitalUnited States
Designs and builds autonomous vulnerability automation pipelines using AI tools to discover assets, scan vulnerabilities, harden configurations, and auto-remediate in cloud-native environments. Requires 5+ years in security engineering, DevSecOps, IaC, and cloud security tools.
170k – 190k/yr
Remote5+ YOESecurity Engineering
Software Engineer, Security Infrastructure
SiftstackMarina del Rey, CA +2
Builds and automates security controls, tooling, and compliance for AWS, Kubernetes, and CI/CD in cloud-native environments. Requires 4+ years in security engineering with hands-on IaC, scripting, and frameworks like SOC 2/FedRAMP.
170k – 220k/yr
Hybrid4+ YOESecurity Engineering
Incident Response Security Engineer
ClickhouseUnited States
Handles security incidents, develops detection and response processes, maintains logging platforms, and automates risk mitigation for cloud services. Requires experience in incident response, threat modeling, cloud security, and programming in Golang/Python.