Skip to content
VannevarVannevar

Application Security Engineer

The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.

About the job

Responsibilities

  • Implement and deploy SAST, SCA, secrets scanning, DAST, and container/IaC checks in CI/CD pipelines.
  • Partner with development teams to conduct threat modeling, review critical pull requests, and promote secure-by-default practices.
  • Drive shift-left vulnerability detection and remediation across the software development lifecycle.
  • Coordinate with DevOps on application security issues spanning application and infrastructure layers.
  • Support product incident response and incorporate lessons learned into code, documentation, and processes.

Requirements

  • 5+ years of application or product security experience.
  • Hands-on experience securing web applications and automating application security workflows.
  • Familiarity with DevSecOps, container security, and patching.
  • Experience with GitHub Actions, Python, and TypeScript/JavaScript.
  • Clear, concise communication skills, including the ability to translate security risk for engineers.

Nice to Have

  • Experience securing LLM workflows.
  • Experience with the NIST Risk Management Framework.
  • Software security experience at a U.S. defense contractor.
  • Active security clearance or ability to obtain one.
  • Willingness to travel onsite.

Compensation and Benefits

  • Salary: $160,000–$210,000, plus equity and 401(k) match.
  • Health, dental, and vision insurance.
  • 401(k) matching.
  • Mental health benefits.
  • Flexible work environment.
  • Pet and childcare reimbursement during travel.
  • Unlimited PTO.

Skills

SAST, Sca, DAST, Secrets Scanning, Container Security, Infrastructure As Code, CI/CD, Threat Modeling, DevSecOps, GitHub Actions, Python, TypeScript, JavaScript, Nist Risk Management Framework, Llm Security

Wiz

Wiz

Washington, DC

Cyber Threat Intel Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.

Fireworks AI

Fireworks AI

San Mateo, CA

GRC Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.

Zoox

Zoox

Foster City, CA

Sensing and Perception System Safety Engineer
$170k+/yrHybrid3+ YOESecurity Engineering

Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.

Greptile

Greptile

San Francisco, CA

Security Engineer
$170k+/yrOn-site3+ YOESecurity Engineering

Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.