Skip to content
DecagonDecagon

Senior Software Engineer, Application Security

Leads application security strategy and implementation for an AI-powered conversational platform, partnering with engineering teams on secure development, testing, code reviews, vulnerability remediation, and incident response. Requires 5+ years of application security experience and strong software engineering expertise.

About the job

Responsibilities

  • Design and implement application security controls across an AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
  • Collaborate with product engineering teams to integrate security throughout the software development lifecycle, from design and coding through pull requests and deployment.
  • Establish application security testing programs, including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored to AI applications.
  • Lead security code reviews and architecture assessments, focusing on AI model integration points and customer data handling.
  • Build security tooling and automation to help developers identify and remediate vulnerabilities quickly while maintaining development velocity.
  • Respond to security incidents involving application vulnerabilities and coordinate remediation and post-incident improvements.

Requirements

  • 5+ years of hands-on application security engineering experience.
  • Expertise in secure software development, threat modeling, secure code review, and vulnerability assessment.
  • Strong software engineering background with the ability to review code across multiple languages and frameworks used in AI/ML applications.
  • Experience implementing application security testing tools and integrating security into CI/CD pipelines.
  • Knowledge of the OWASP Top 10, common application vulnerabilities, and modern application security frameworks.
  • Proven ability to work with engineering teams to remediate security findings while balancing security and business requirements.

Nice-to-Haves

  • Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections.
  • Experience with large-scale, multi-tenant SaaS applications handling sensitive customer data.
  • Familiarity with Google Cloud application security services and container security best practices.
  • Knowledge of SOC 2, ISO 27001, and GDPR compliance requirements from an application security perspective.
  • Experience with Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar security tools.

Compensation and Benefits

  • $200,000–$330,000 plus equity.
  • Medical, dental, and vision benefits for employees and families.
  • Life insurance and disability benefits.
  • Retirement plan.
  • Parental leave.
  • Fertility and family-building benefits.
  • Monthly wellness and lifestyle stipend.
  • Daily office lunches and snacks.
  • Flexible vacation policy.

Skills

Application Security, Threat Modeling, Secure Code Review, Vulnerability Management, SAST, DAST, Iast, CI/CD, Owasp Top 10, GCP, Container Security, Semgrep, Codeql, Prompt Injection, Model Extraction

Snowflake

Snowflake

Menlo Park, CA
Senior Software Engineer - Cloud Security
$200k+/yrHybrid5+ YOESecurity Engineering

Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.

Atomicmachines

Atomicmachines

Emeryville, CA
Senior Manager - Network and Information Security
$200k+/yrOn-site10+ YOESecurity Engineering

Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.

Anyscale

Anyscale

India
Senior Detection and Response Engineer
$200k+/yrOn-site6+ YOESecurity Engineering

Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.

Anyscale

Anyscale

San Francisco, CA

Senior Cloud Security Engineer
$200k+/yrHybrid8+ YOESecurity Engineering

Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.