Application Security Engineer
Application Security Engineer identifies systemic security gaps, builds tooling and automation like custom linters and static analysis, conducts code reviews and threat modeling, and drives vulnerability remediation in a TypeScript/Python codebase. Requires 5+ years hands-on AppSec experience and strong engineering depth.
About the job
Responsibilities
- Identify systemic security gaps in our codebase and engineering workflows, and work with engineering teams to design and ship durable solutions; you’ll drive solutions, not just surface problems
- Build security tooling, automation, and code-level controls that address classes of vulnerabilities, including custom linters, static analysis rules, and automated checks, shifting the cost of catching issues left rather than handling them one at a time or after they’ve reached production
- Conduct in-depth code reviews and security design reviews for significant product initiatives, with the technical depth to engage meaningfully with architectural tradeoffs rather than just flag issues for others to resolve
- Drive threat modeling and security assessments for new features, and translate security requirements into practical engineering guidance that developers can actually act on
- Contribute to the team’s evolving approach to security as AI-assisted development scales internally, including how faster and higher-volume code production changes how we find, prioritize, and fix risks
- Triage, track, and drive remediation of vulnerabilities with product engineering teams, and contribute to our penetration testing and bug bounty programs
Requirements
- 5+ years of hands-on experience in application security and security engineering: you’ve built things, not only assessed them, and your background is not mainly consulting, audit, or compliance work
- The ability to operate independently with good judgment in a fast-moving environment: you prioritize well by understanding the needs of the business and our shared objectives, make calls with incomplete information, and know when to move fast versus when to slow down and get it right, or escalate and ask for help
- Communication that earns trust: you can make security legible to engineers without being preachy, and you measure your impact by how well you’ve supported the business, not by how many issues you catalogued
- A track record of shipping security tooling or automation that improved things for more than one team
- Genuine engineering depth: you can read, reason about, and review code at the level needed to find real bugs and understand their root causes, not just pattern-match to a checklist
- Comfort working in TypeScript and Python: Retool’s platform is built in TypeScript and our security tooling leans on Python, you’ll need to be productive in both and not just conversant
- Strong AppSec fundamentals: threat modeling, secure code review, a working understanding of common vulnerability classes and, importantly, how to address them durably rather than symptomatically
- A pragmatic, signal-oriented relationship with AI tooling: you reach for it where it genuinely sharpens your work, you’re skeptical where it doesn’t, and you’re thinking about what developer-side AI adoption means for how security risk compounds at scale
Nice to Have
- Offensive security experience like bug bounty, CTF participation, redteam, or pentesting work
- Experience building or contributing to SAST pipelines, custom static analysis rules, or automated security testing infrastructure
- Prior experience at a startup or high-growth scaleup, where security programs aren’t fully pre-defined and priorities shift
Compensation
Base pay range: $231,900 – $318,250 per year
Skills
TypeScript, Python, Threat Modeling, Secure Code Review, Static Analysis, SAST, Custom Linters, Automated Security Testing, Penetration Testing, Bug Bounty
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.