Senior Application Security Engineer
Leads application security initiatives across products, APIs, distributed systems, and AI-enabled applications. The role requires at least five years of security or software engineering experience, strong threat-modeling and architecture skills, and the ability to build security automation and drive remediation.
About the job
Responsibilities
- Lead application security projects from planning through implementation, coordinating contributors and dependencies.
- Conduct threat modeling and security architecture reviews for customer-facing applications, APIs, distributed services, and AI/ML systems.
- Design and implement secure-by-default software development lifecycle controls, including secure coding standards, API protections, automated testing, CI/CD safeguards, and secrets management.
- Partner with engineering teams to identify systemic vulnerabilities, evaluate remediation options, and drive resolution of high-risk issues.
- Build services and automation for vulnerability detection, prioritization, validation, and prevention.
- Assess AI-enabled products and developer workflows, including GenAI integrations, agentic systems, model inputs and outputs, sensitive-data handling, and access boundaries.
- Provide technical leadership during high-severity application security incidents and drive durable follow-up improvements.
- Contribute to design and code reviews, document reusable patterns, mentor engineers, and improve application security practices.
Requirements
- 5+ years of experience in security engineering, software engineering, or a related technical role, including 2+ years focused on application or product security.
- Experience leading security projects involving multiple contributors or partner teams.
- Experience with threat modeling and security architecture reviews for complex production applications.
- Experience developing production software or security automation in Java, Python, Ruby, Go, or a similar language.
- Experience implementing application security controls across the software development lifecycle, including API security, secure coding standards, SAST, DAST, SCA, CI/CD security, or secrets management.
- Experience identifying, validating, prioritizing, and remediating application vulnerabilities.
- Experience securing cloud-native or distributed systems, including web applications, APIs, or microservices.
- Experience investigating significant application security issues or incidents and translating findings into corrective engineering work.
Nice-to-haves
- Experience building reusable application security guardrails, platforms, or automation adopted by multiple engineering teams.
- Experience securing modern frontend frameworks, REST or GraphQL APIs, microservices, and event-driven architectures.
- Familiarity with AI/ML and GenAI security risks, including prompt injection, insecure tool use, sensitive-data exposure, and model supply-chain risks.
- Experience using risk metrics or program data to prioritize work and measure security outcomes.
- Experience mentoring security or software engineers and improving quality through design and code reviews.
- Experience partnering with Legal, Risk, Compliance, or Audit teams in a regulated environment.
- Security certifications such as CISSP, CSSLP, CCSP, or AWS Security Specialty, or equivalent practical expertise.
Compensation
- Anticipated base salary: $166,900–$230,900 USD.
- Additional compensation may include target bonuses, equity compensation, and benefits.
Skills
Threat Modeling, Security Architecture, Api Security, SAST, DAST, Sca, Ci/Cd Security, Secrets Management, Python, Java, Go, Cloud Security, Microservices, Genai Security, Vulnerability Management
Similar jobs
Security Engineering jobsLeads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Build and operate scalable malware-analysis, threat-enrichment, and graph-intelligence systems that power security research and detection. The role requires 6+ years of security pipeline or threat-intelligence experience, strong Python or Go skills, and expertise in cloud and distributed systems.
Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.