Staff Application Security Engineer
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
About the job
Responsibilities
- Innovate with AI and deliver security solutions to mitigate application vulnerabilities
- Run security code tests (SAST, SCA) and partner with engineers to remediate unsafe code
- Create threat models and engage technology teams to review and document risks
- Guide leadership on security architecture, design and best AppSec practices
- Train and upskill engineers on safe coding and vulnerability management
- Assist penetration testing initiatives and/or help manage bug bounties
- Support administration of AWS Control Tower and IAM provisioning
- Interact with the security community and keep aware of trends
Requirements
- 6+ years of application or product security inclusive of reviewing Python code
- Experience with innovating and delivering solutions related to vulnerability management
- Deep knowledge of AWS and Lambda security architecture and AWS Control Tower
- Strong understanding and adoption of AI technologies
- Bachelor’s degree in Computer Science or Engineering highly preferred
- Exceptional customer service and people skills
Tools
- Github Suite (Advanced Security, Actions, Copilot)
- Python
- Terraform
- AWS Lambda, DynamoDB, S3, SNS, SQS, IAM, VPCs
- ChatGPT
- Snowflake
- SQL
Skills
Application Security, Python, AWS, AWS Lambda, Aws Control Tower, SAST, Sca, Threat Modeling, Terraform, IAM
Similar jobs
Security Engineering jobsDesign and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.