Senior Software Engineer, Application Security
Leads application security strategy and implementation for an AI-powered conversational platform, partnering with engineering teams on secure development, testing, code reviews, vulnerability remediation, and incident response. Requires 5+ years of application security experience and strong software engineering expertise.
About the job
Responsibilities
- Design and implement application security controls across an AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
- Collaborate with product engineering teams to integrate security throughout the software development lifecycle, from design and coding through pull requests and deployment.
- Establish application security testing programs, including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored to AI applications.
- Lead security code reviews and architecture assessments, focusing on AI model integration points and customer data handling.
- Build security tooling and automation to help developers identify and remediate vulnerabilities quickly while maintaining development velocity.
- Respond to security incidents involving application vulnerabilities and coordinate remediation and post-incident improvements.
Requirements
- 5+ years of hands-on application security engineering experience.
- Expertise in secure software development, threat modeling, secure code review, and vulnerability assessment.
- Strong software engineering background with the ability to review code across multiple languages and frameworks used in AI/ML applications.
- Experience implementing application security testing tools and integrating security into CI/CD pipelines.
- Knowledge of the OWASP Top 10, common application vulnerabilities, and modern application security frameworks.
- Proven ability to work with engineering teams to remediate security findings while balancing security and business requirements.
Nice-to-Haves
- Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections.
- Experience with large-scale, multi-tenant SaaS applications handling sensitive customer data.
- Familiarity with Google Cloud application security services and container security best practices.
- Knowledge of SOC 2, ISO 27001, and GDPR compliance requirements from an application security perspective.
- Experience with Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar security tools.
Compensation and Benefits
- $200,000–$330,000 plus equity.
- Medical, dental, and vision benefits for employees and families.
- Life insurance and disability benefits.
- Retirement plan.
- Parental leave.
- Fertility and family-building benefits.
- Monthly wellness and lifestyle stipend.
- Daily office lunches and snacks.
- Flexible vacation policy.
Skills
Application Security, Threat Modeling, Secure Code Review, Vulnerability Management, SAST, DAST, Iast, CI/CD, Owasp Top 10, GCP, Container Security, Semgrep, Codeql, Prompt Injection, Model Extraction
Similar jobs
Security Engineering jobsBuild secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.