# Senior Application Security Engineer

**Company:** [Siftstack](https://hotfix.jobs/companies/siftstack)
**Location:** Marina Del Rey, CA
**Role:** Security Engineering
**Salary:** $180k – $230k/yr
**Experience:** 5+ years
**Skills:** Go, Rust, Application Security, Threat Modeling, Cryptography, SAST, Software Composition Analysis, Secret Scanning, Fuzzing, CI/CD, Sigstore, Slsa, Sbom, Authentication, Authorization
**Posted:** 2026-08-20

> The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.

## Job Description

## Responsibilities
- Build secure-by-default patterns, libraries, and standards for authentication, authorization, input handling, and cryptography.
- Own dependency integrity, artifact signing, and build-pipeline trust for self-managed and air-gapped deployments.
- Partner with engineering teams on threat modeling and secure design for features and architectural changes across a distributed, polyglot system.
- Own application security tooling in CI/CD, including SAST, software composition analysis, secret scanning, and fuzzing.
- Tune security tooling for actionable findings and drive remediation with owning teams.
- Improve engineering security fluency through design reviews, documentation, and collaboration.

## Requirements
- 5+ years building production software, including direct security ownership of a shipped codebase.
- Fluency reading and reviewing a compiled systems language, with depth in Go or Rust.
- Strong application security knowledge covering web and API vulnerabilities, authentication and authorization patterns, and applied cryptography.
- Experience applying threat modeling and design review to distributed systems.
- Hands-on experience integrating SAST, SCA, and secret scanning into developer workflows and CI/CD.
- Experience building security tooling or libraries adopted by other teams.
- Clear communication with engineers and leadership, including explaining risk and tradeoffs.
- U.S. citizenship required.

## Nice-to-haves
- Experience securing software deployed to customer-controlled, on-premise, or air-gapped environments.
- Familiarity with Sigstore, SLSA, and SBOM generation.
- Experience fuzzing native or high-throughput data paths.
- Exposure to regulated environments such as defense or aerospace.

## Compensation and Benefits
- Salary range: $180,000–$230,000 per year.
- Equity and benefits.

## Similar jobs

- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Security Engineer, Threat & Offensive Security](https://hotfix.jobs/jobs/9e88bf55-b93e-4acd-ae0b-a8850f2c805e) - Valon - Remote - $180k – $230k/yr
- [Senior Product Security Engineer](https://hotfix.jobs/jobs/ee4b6e89-8ca0-45e7-9cbf-da0994206d99) - Anyscale - $180k – $210k/yr
- [Compliance Manager](https://hotfix.jobs/jobs/90cc18a6-7467-4675-96aa-770c09c5a6ee) - Anyscale - San Francisco, CA - $180k – $230k/yr
- [Security Operations Lead](https://hotfix.jobs/jobs/6494f34e-ec68-46c4-a932-f070ac908ddf) - Fireworks AI - Remote - $180k – $210k/yr

**Apply:** https://hotfix.jobs/jobs/4bd73e3b-28a6-4dae-956a-f38222e41da3
**Canonical:** https://hotfix.jobs/jobs/4bd73e3b-28a6-4dae-956a-f38222e41da3