Application Security Engineer
Partners with engineers to embed security in AI product development through threat modeling, secure reviews, tooling, and vulnerability management. Requires 5+ years experience, programming proficiency, and offensive security mindset.
About the job
Responsibilities
- Help secure AI products and internal tools introducing novel security risks
- Lead “shift left” security efforts in the software development lifecycle
- Conduct secure design reviews and threat modeling to identify risks
- Develop tooling for security code reviews and vulnerability remediation
- Manage vulnerability management program with data pipelines and prioritization
- Oversee bug bounty program, validate submissions, and coordinate remediation
- Collaborate with product engineers to instill security best practices
- Develop security policies, standards, playbooks, and conduct training
You may be a good fit if you
- Have 5+ years of hands-on experience in application and infrastructure security, including cloud and containerized environments
- Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)
- Lead with empathy and collaborate cross-functionally
- Leverage creative thinking to reduce risk through secure design
- Possess broad security knowledge across domains
- Distill complex concepts into clear actions
- Proactive mindset for threat modeling and secure code review
- Strong grasp of offensive security
- Experience with modern application stacks and security tools
- Balance security with business objectives
Strong candidates may also
- Expertise securing cloud environments and microservices (Kubernetes, Docker, AWS/GCP)
- Exposure to offensive security (bug bounty, pen testing, red team)
- Familiarity with AI/ML security risks (prompt injection, data poisoning)
- Experience building security tools and automation
- Solid knowledge of software and security engineering principles
- Excellent communication skills
- Thrive in fast-paced environments
Logistics
Education requirements: At least a Bachelor's degree in a related field or equivalent experience.
Annual Salary: $300,000—$405,000 USD
Skills
Python, Rust, Go, Java, Kubernetes, Docker, AWS, GCP, Threat Modeling, Vulnerability Management
Similar jobs
Security Engineering jobsConduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.
Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.
This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.
Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.
Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.