# Senior Application Security Engineer

**Company:** [Starburst](https://hotfix.jobs/companies/starburst)
**Location:** Boston, MA
**Role:** Security Engineering
**Salary:** $175k – $215k/yr
**Experience:** 5+ years
**Skills:** Application Security, Product Security, SDLC, Threat Modeling, Red Teaming, Threat Hunting, Vulnerability Management, Container Security, Jvm, Software Supply Chain Security, SAST, Sca, DAST, AI
**Posted:** 2026-08-25

> Own and scale Starburst’s application and product security program through secure-by-default engineering, automated vulnerability management, threat modeling, and autonomous offensive testing. The role requires 5–7 years of security-focused experience, strong software supply chain expertise, and the ability to engage enterprise customers and lead engineers.

## Job Description

## Responsibilities
- Own and mature the Application Security program across a large engineering organization.
- Embed secure-by-default patterns, guardrails, threat modeling, and automated checks into the software development lifecycle, including AI-assisted development.
- Build autonomous red-teaming and threat hunting capabilities using AI and automation.
- Manage vulnerabilities across self-managed enterprise and SaaS products, including container images, third-party dependencies, and first-party code.
- Automate vulnerability detection, triage, routing, and remediation using reachability and exploitability analysis.
- Own application and software supply chain security tooling, including SAST, SCA, DAST, and container scanning.
- Manage third-party penetration testing and the Vulnerability Disclosure Program.
- Advise enterprise customers and leadership on product security posture and assurance.
- Report on product security in executive, customer, and audit conversations.
- Lead and mentor engineers.

## Requirements
- Bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.
- 5–7 years of experience in application security, product security, software engineering with a security focus, or a related technical role.
- Deep knowledge of application and product security fundamentals, including exploitability assessment.
- Experience embedding security into the SDLC and scaling security processes across engineering teams.
- Experience managing vulnerabilities for shipped software at scale.
- Strong knowledge of container and image security, JVM dependencies, and software supply chain risks.
- Offensive security experience, including red-teaming or threat hunting against products.
- Threat modeling experience for distributed systems and data platforms.
- Experience using automation and AI to scale security work.
- Experience with enterprise B2B software and direct engagement with enterprise customers on security.
- Experience leading and mentoring engineers.

## Compensation and Benefits
- Salary range: $175,000–$215,000 USD.
- Equity packages through incentive stock options (ISOs).
- Competitive total rewards program, including flexible paid time off and other benefits.

## Similar jobs

- [Senior Security Engineer](https://hotfix.jobs/jobs/b4bd3a90-c9c6-4983-b371-da5d17567c3a) - Jasper - Remote - $174k – $205k/yr
- [Senior GRC Lead](https://hotfix.jobs/jobs/184bbd0f-e014-4dbb-ad67-9e995b7c12bc) - Jasper - Remote - $174k – $205k/yr
- [Compliance Engineer - Public Sector](https://hotfix.jobs/jobs/1664a48a-e3c2-4c6a-91dd-ffcd986273e3) - Wiz - Remote - $174k – $238k/yr
- [Senior Security Engineer, Incident Response](https://hotfix.jobs/jobs/e3eb314c-9387-43d9-ac19-4e000eebb406) - Snowflake - Remote - $176k – $253k/yr
- [Senior Security Engineer, AI Incident Response](https://hotfix.jobs/jobs/78fd3868-4f71-43b6-9cd6-de438376e06d) - Snowflake - Menlo Park, CA - $176k – $253k/yr

**Apply:** https://hotfix.jobs/jobs/50407c37-394b-474e-b261-b30218d87d23
**Canonical:** https://hotfix.jobs/jobs/50407c37-394b-474e-b261-b30218d87d23