Application Security Engineer
The Application Security Engineer embeds security throughout the software development lifecycle through code reviews, threat modeling, security tooling, vulnerability response, and developer mentoring. The role requires 5+ years of application security experience and strong programming skills across cloud-native environments.
About the job
Responsibilities
- Conduct secure code reviews, threat modeling, and architecture assessments to identify and mitigate vulnerabilities early.
- Collaborate with engineering teams to design and implement security features, provide actionable feedback, and embed security into product development.
- Lead security training, workshops, and one-on-one mentoring to upskill developers and foster a security-first culture.
- Integrate SAST/DAST and supply chain security tools into CI/CD pipelines for continuous, automated protection.
- Detect, triage, and respond to application vulnerabilities and incidents, driving remediation and continuous improvement.
- Monitor and address emerging risks in AI infrastructure, LLM pipelines, and third-party dependencies.
Requirements
- 5+ years of experience in application security, including securing cloud-native environments at product-focused technology companies, high-growth startups, or leading AI labs.
- Strong programming and engineering skills.
- Deep expertise in application security, including secure code review, threat modeling, SAST/DAST, supply chain security, product patching, and vulnerability management.
- Experience securing engineering infrastructure, including CI/CD pipelines, secrets management, service-to-service authentication, containerized workloads, and public cloud platforms.
- Hands-on experience collaborating with developers to design and implement security features and best practices.
- Experience educating and mentoring engineers on secure coding, vulnerability remediation, and emerging threats.
- Systems mindset, with the ability to read and contribute to codebases, build security tooling, and integrate security into engineering workflows.
Nice-to-haves
- Experience building internal security tools.
- Contributions to open-source security projects.
Technical Environment
- Frontend: React, TypeScript
- Backend: Golang, Rust
- Cloud: Cloudflare, Google Cloud, AWS, Terraform
- DevOps and tooling: CI/CD pipelines, observability, infrastructure as code
Skills
Application Security, Secure Code Review, Threat Modeling, Sast/Dast, Supply Chain Security, Vulnerability Management, CI/CD, Secrets Management, Containerization, Cloudflare, GCP, AWS, Terraform, React, TypeScript
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Owns corporate security across identities, endpoints, SaaS, email, and workplace AI tools. The role requires 5+ years of corporate, enterprise, or endpoint security experience, strong IAM and MDM expertise, coding ability, and practical risk-based security judgment.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.