Skip to content
WriterWriter

Security Engineer, Application Security

Build and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.

About the job

Responsibilities

  • Conduct threat modeling with product teams and design secure architectures for new features.
  • Own and evolve the application security program, including SAST/DAST scanning in CI/CD pipelines, security code reviews, and vulnerability-detection automation.
  • Establish secure coding standards and create reusable security patterns and libraries.
  • Design and recommend security features and products for customer environments.
  • Integrate AI agents to increase security-team and engineering velocity while proactively minimizing risk.
  • Lead security assessments and penetration testing for applications, AI services, and APIs.
  • Design and implement controls protecting data pipelines, model-training environments, and customer-facing AI agents.
  • Research emerging AI/ML security threats, including LLM and generative-AI attack vectors, and build proactive defenses.

Requirements

  • 4+ years of hands-on application security engineering experience securing large-scale production systems.
  • Understanding of developer experience and workflows for shipping features and products.
  • Expertise in at least two programming languages, such as Python, Java, Go, or JavaScript/TypeScript.
  • Ability to read and review code across multiple languages, including business logic and security implications.
  • Knowledge of SAST/DAST solutions, vulnerability-management platforms, security-testing frameworks, and DevSecOps practices.
  • Strong communication skills for explaining security concepts to technical and non-technical audiences.
  • Builder's mindset focused on automation, scalability, and enabling engineering teams.

Benefits and Perks

  • Generous paid time off and company holidays.
  • Medical and dental insurance.
  • 16 weeks of paid parental leave for all parents.
  • Fertility and family-planning support.
  • Early-detection cancer testing.
  • Competitive pension scheme and company contribution.
  • Wellness, learning and development, and work-life stipends.
  • Company-wide and team off-sites.
  • Company stock options.

Skills

Application Security, Threat Modeling, SAST, DAST, CI/CD, Python, Java, Go, JavaScript, TypeScript, DevSecOps, Penetration Testing, Llm Security, Vulnerability Management, Secure Coding

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

Twilio

Twilio

United Kingdom
Security Engineer, Incident Response
No salary listedRemote3+ YOESecurity Engineering

Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.

Docker

Docker

United Kingdom
Senior Security Engineer, Offensive Security
€119k+/yrRemote5+ YOESecurity Engineering

Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.