Skip to content
NerdioNerdio

Application Security Architect

Leads the development and evolution of the Application Security program, integrating security practices into SDLC through threat modeling, code reviews, and pen testing. Collaborates with engineering teams on web, mobile, and API security for a SaaS platform; requires 10+ years experience building AppSec from inception.

About the job

What You'll Do

  • Establish and continuously improve the AppSec program's strategy, processes, and tooling.
  • Collaborate with engineers to integrate security best practices into design reviews, threat modeling, code reviews, and penetration testing.
  • Participate in secure code review and penetration testing efforts.
  • Contribute to deep-dive security reviews of web, mobile, and API products.
  • Participate in security training and share learnings with the engineering team.
  • Assist in incident response.
  • Gain exposure to SAST/DAST tools and risk assessment.
  • Mentor junior members of the AppSec team.

What we are looking for

  • 10+ years of experience in application security or related field.
  • Led inception of Application Security program from the ground up.
  • Solid understanding of security fundamentals and common vulnerabilities (e.g., XSS, CSRF, SQL Injection).
  • Ability to identify risks and collaborate with engineers.
  • Communicate security concepts to technical and non-technical audiences.

Preferred Qualifications

  • Familiarity with programming languages (C#, React, JavaScript, REST APIs).
  • Active in security community (B-sides, OWASP, GitLab contributions).

Benefits and Incentives

  • Competitive Base and Incentive Plan
  • Stock Options
  • Health and Welfare Plans*
  • Life and Disability Plans*
  • Retirement Plan*
  • Unlimited Flexible Paid Time Off, including birthday off
  • Collaborative Team Culture*

Skills

Application Security, Threat Modeling, SAST, DAST, Penetration Testing, Code Review, Owasp, Xss, Csrf, Sql Injection, C#, React, JavaScript, REST APIs

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Okta

Okta

Bellevue, WA
Staff Identity Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.