Senior Application Security Engineer
Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.
About the job
Responsibilities
- Own and mature the Application Security program across a large engineering organization.
- Embed secure-by-default patterns, guardrails, threat modeling, and automated checks into the software development lifecycle, including AI-assisted development.
- Build autonomous red-teaming and threat hunting capabilities using AI and automation.
- Manage vulnerabilities across self-managed enterprise and SaaS products, including container images, third-party dependencies, and first-party code.
- Automate vulnerability detection, triage, routing, and remediation using reachability and exploitability analysis.
- Own application and software supply chain security tooling, including SAST, SCA, DAST, and container scanning.
- Manage third-party penetration testing and the Vulnerability Disclosure Program.
- Advise enterprise customers and leadership on product security posture and assurance.
- Report on product security in executive, customer, and audit conversations.
- Lead and mentor engineers.
Requirements
- Bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.
- 5–7 years of experience in application security, product security, software engineering with a security focus, or a related technical role.
- Deep knowledge of application and product security fundamentals, including exploitability assessment.
- Experience embedding security into the SDLC and scaling security processes across engineering teams.
- Experience managing vulnerabilities for shipped software at scale.
- Strong knowledge of container and image security, JVM dependencies, and software supply chain risks.
- Offensive security experience, including red-teaming or threat hunting against products.
- Threat modeling experience for distributed systems and data platforms.
- Experience using automation and AI to scale security work.
- Experience with enterprise B2B software and direct engagement with enterprise customers on security.
- Experience leading and mentoring engineers.
Compensation and Benefits
- Salary range: $175,000–$215,000 USD.
- Equity packages through incentive stock options (ISOs).
- Competitive total rewards program, including flexible paid time off and other benefits.
Skills
Application Security, Product Security, SDLC, Threat Modeling, Red Teaming, Threat Hunting, Vulnerability Management, Container Security, Jvm, Software Supply Chain Security, SAST, Sca, DAST, AI
Similar jobs
Security Engineering jobsThe Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
Leads product security incident response for Snowflake’s AI products and infrastructure, developing detection, containment, and remediation capabilities for LLM and agentic threats. Requires 5+ years in security, incident command experience, cloud-native expertise, and strong knowledge of AI attack surfaces.