Senior Application Security Engineer
Integrates security into product design, conducts threat modeling and risk assessments, manages secure development pipelines, and triages vulnerabilities. Requires 5+ years in app security, Kubernetes expertise, and strong collaboration with engineering teams.
About the job
What You’ll Do
- Collaborate with product and engineering teams to integrate security principles into the design and architecture of products.
- Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across the full product surface.
- Manage the Secure Development pipeline including code security and 3rd party library supply chain security.
- Stay current on emerging standards and guidance (e.g. OWASP Top 10 for LLMs, MCP security specifications) and translate these into actionable internal policy.
- Triage Bug Bounty findings and responsibly disclosed vulnerabilities.
- Participate in on-call rotation.
What You’ll Bring
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field (or equivalent experience).
- 5+ years in application or product security or a related role.
- Proven partnership with engineering teams, bringing security expertise to the planning and development process.
- Knowledge of encryption, authentication, and secure communication protocols.
- Familiarity with tools like SAST, DAST, and penetration testing frameworks.
- Deep understanding of application architecture and design principles, ability to effectively identify vulnerabilities across multiple programming languages.
- Kubernetes security posture management and auditing, including workload hardening, RBAC design, and admission control.
- Demonstrated experience with multi-tenant security architecture, including data plane isolation, control plane hardening, and cross-tenant data leakage prevention.
- Excellent collaboration and communication skills.
- Expertise in at least one programming language, familiarity with Python and Go.
Nice to Have
- Distributed computing and related vulnerability experience.
- Running a Security Champions program.
- Open Source automation or automation projects.
- Expertise in other areas of security.
- Security conference talks or published research.
Compensation
- Estimated pay range: $180,000 - $225,000, depending on qualifications and location.
- Eligible to participate in Temporal's equity plan.
Skills
Kubernetes, RBAC, SAST, DAST, Penetration Testing, Python, Go, Owasp, Threat Modeling, Encryption, Authentication, Multi-Tenant Security
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.