Skip to content
OneleetOneleet

Application Security Engineer

Application Security Engineer building and tuning the security judgment layer for a cybersecurity platform, integrating tooling, reducing noise, and partnering with product and engineering teams.

About the job

Key Responsibilities

  • Own the integration, configuration, and output quality of security tooling that powers our platform
  • Tune outputs to maximize signal and minimize noise — decide what to surface, what to suppress, and what to enrich
  • Design rules, severity scoring, and triage flows that make findings actionable rather than overwhelming
  • Build the security judgment layer on top of underlying tooling — context-aware prioritization and exploitability reasoning
  • Partner with engineers on how findings are presented in the UI and how remediation flows work
  • Work with PM and design on roadmap priorities, providing the security expertise that drives what to build next
  • Review and shape architectural choices that affect security outcomes
  • Engage with customers directly to understand how they use the platform and what's blocking adoption
  • Benchmark our output quality against competitors and close gaps where they exist
  • Contribute back to the open source security tooling we depend on where it makes sense

Qualifications

  • 5+ years of application security experience, with significant time shipping security products
  • Strong programming skills in at least one of Go, Python, or TypeScript
  • Hands-on experience tuning security tooling for production use — reducing false positives, building suppression logic, designing severity models
  • Understanding of vulnerability research, CVE/CWE taxonomies, and exploit reasoning
  • Experience determining what makes a security finding actionable vs. just technically true
  • Excellent communication skills and comfort working directly with customers
  • Pragmatic approach to building things fast without unnecessarily complicating things
  • Experience thriving in a fast-moving, start-up engineering environment

Nice-to-Haves

  • Prior experience shipping a security product at a vendor
  • Contributions to open source security tooling
  • Offensive security background or OSCP / similar certifications
  • Hands-on experience with LLM agents, tool use, or autonomous AI systems

Skills

Application Security, Go, Python, TypeScript, Security Tooling, Vulnerability Research, Cve, Cwe, False Positive Reduction, Severity Scoring, Exploit Reasoning, Open Source Security

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.