Skip to content
LovableLovable

Application Security Engineer

The Application Security Engineer embeds security throughout the software development lifecycle through code reviews, threat modeling, security tooling, vulnerability response, and developer mentoring. The role requires 5+ years of application security experience and strong programming skills across cloud-native environments.

About the job

Responsibilities

  • Conduct secure code reviews, threat modeling, and architecture assessments to identify and mitigate vulnerabilities early.
  • Collaborate with engineering teams to design and implement security features, provide actionable feedback, and embed security into product development.
  • Lead security training, workshops, and one-on-one mentoring to upskill developers and foster a security-first culture.
  • Integrate SAST/DAST and supply chain security tools into CI/CD pipelines for continuous, automated protection.
  • Detect, triage, and respond to application vulnerabilities and incidents, driving remediation and continuous improvement.
  • Monitor and address emerging risks in AI infrastructure, LLM pipelines, and third-party dependencies.

Requirements

  • 5+ years of experience in application security, including securing cloud-native environments at product-focused technology companies, high-growth startups, or leading AI labs.
  • Strong programming and engineering skills.
  • Deep expertise in application security, including secure code review, threat modeling, SAST/DAST, supply chain security, product patching, and vulnerability management.
  • Experience securing engineering infrastructure, including CI/CD pipelines, secrets management, service-to-service authentication, containerized workloads, and public cloud platforms.
  • Hands-on experience collaborating with developers to design and implement security features and best practices.
  • Experience educating and mentoring engineers on secure coding, vulnerability remediation, and emerging threats.
  • Systems mindset, with the ability to read and contribute to codebases, build security tooling, and integrate security into engineering workflows.

Nice-to-haves

  • Experience building internal security tools.
  • Contributions to open-source security projects.

Technical Environment

  • Frontend: React, TypeScript
  • Backend: Golang, Rust
  • Cloud: Cloudflare, Google Cloud, AWS, Terraform
  • DevOps and tooling: CI/CD pipelines, observability, infrastructure as code

Skills

Application Security, Secure Code Review, Threat Modeling, Sast/Dast, Supply Chain Security, Vulnerability Management, CI/CD, Secrets Management, Containerization, Cloudflare, GCP, AWS, Terraform, React, TypeScript

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Lovable

Lovable

Stockholm, Sweden

Security Engineer, Corporate
No salary listedOn-site5+ YOESecurity Engineering

Owns corporate security across identities, endpoints, SaaS, email, and workplace AI tools. The role requires 5+ years of corporate, enterprise, or endpoint security experience, strong IAM and MDM expertise, coding ability, and practical risk-based security judgment.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.