Skip to content
SiftstackSiftstack

Senior Application Security Engineer

The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.

About the job

Responsibilities

  • Build secure-by-default patterns, libraries, and standards for authentication, authorization, input handling, and cryptography.
  • Own dependency integrity, artifact signing, and build-pipeline trust for self-managed and air-gapped deployments.
  • Partner with engineering teams on threat modeling and secure design for features and architectural changes across a distributed, polyglot system.
  • Own application security tooling in CI/CD, including SAST, software composition analysis, secret scanning, and fuzzing.
  • Tune security tooling for actionable findings and drive remediation with owning teams.
  • Improve engineering security fluency through design reviews, documentation, and collaboration.

Requirements

  • 5+ years building production software, including direct security ownership of a shipped codebase.
  • Fluency reading and reviewing a compiled systems language, with depth in Go or Rust.
  • Strong application security knowledge covering web and API vulnerabilities, authentication and authorization patterns, and applied cryptography.
  • Experience applying threat modeling and design review to distributed systems.
  • Hands-on experience integrating SAST, SCA, and secret scanning into developer workflows and CI/CD.
  • Experience building security tooling or libraries adopted by other teams.
  • Clear communication with engineers and leadership, including explaining risk and tradeoffs.
  • U.S. citizenship required.

Nice-to-haves

  • Experience securing software deployed to customer-controlled, on-premise, or air-gapped environments.
  • Familiarity with Sigstore, SLSA, and SBOM generation.
  • Experience fuzzing native or high-throughput data paths.
  • Exposure to regulated environments such as defense or aerospace.

Compensation and Benefits

  • Salary range: $180,000–$230,000 per year.
  • Equity and benefits.

Skills

Go, Rust, Application Security, Threat Modeling, Cryptography, SAST, Software Composition Analysis, Secret Scanning, Fuzzing, CI/CD, Sigstore, Slsa, Sbom, Authentication, Authorization

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Valon

Valon

United States

Senior Security Engineer, Threat & Offensive Security
$180k+/yrRemote5+ YOESecurity Engineering

Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.

Anyscale

Anyscale

India
Senior Product Security Engineer
$180k+/yrOn-site8+ YOESecurity Engineering

Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.

Anyscale

Anyscale

San Francisco, CA

Compliance Manager
$180k+/yrOn-site7+ YOESecurity Engineering

Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.

Fireworks AI

Fireworks AI

San Mateo, CA
Security Operations Lead
$180k+/yrRemote7+ YOESecurity Engineering

Build and lead Fireworks AI’s security operations function, owning detection engineering, incident response, threat intelligence, and SecOps workflows. The role requires 7+ years of security experience, hands-on EDR and cloud security expertise, strong Python automation skills, and the ability to grow an IC function into a team.