Senior Security Engineer, Product & Application Security
Senior Security Engineer leading application security reviews, DevSecOps initiatives, and secure architecture for cloud-native systems. Requires strong product security experience and scripting background.
About the job
What you'll do
- Perform application security reviews and threat modeling
- Lead secure SDLC and DevSecOps initiatives
- Enhance CI/CD and software supply chain security
- Secure web, mobile, and API environments
- Drive product security engineering projects
- Develop security tooling and automation
- Advance AI/CV and emerging AI security initiatives
- Manage security testing and vulnerability remediation
- Facilitate developer security enablement and education
- Provide secure architecture guidance and design reviews
What we're looking for
- Strong application and product security experience
- Experience with DevSecOps and secure SDLC practices
- Experience securing cloud-native distributed systems
- Strong understanding of modern application architectures and APIs
- Experience with CI/CD security tooling
- Strong scripting and software engineering background
- Ability to partner closely with engineering organizations
Nice to have
- Familiarity with AI/ML security concepts
- Experience in SaaS, consumer technology, or high-scale environments
Skills
Application Security, Threat Modeling, DevSecOps, Secure Sdlc, Ci/Cd Security, Cloud Security, Api Security, Scripting, Software Engineering, Ai/Ml Security
Similar jobs
Security Engineering jobsLeads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.
Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.