Skip to content
WriterWriter

Security Engineer, Application Security

Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.

About the job

Responsibilities

  • Conduct threat modeling with product teams and design secure architectures for new features.
  • Own and evolve the application security program, including SAST/DAST scanning in CI/CD pipelines, security code reviews, and vulnerability-detection automation.
  • Establish secure coding standards and create reusable security patterns and libraries.
  • Design and recommend security features and products for customer environments.
  • Integrate AI agents to improve security-team and engineering velocity while minimizing risk.
  • Lead security assessments and penetration testing of applications, AI services, and APIs; coordinate remediation at scale.
  • Design and implement controls for data pipelines, model-training environments, and customer-facing AI agents.
  • Research LLM and generative-AI attack vectors and build defenses against emerging threats.

Requirements

  • At least 4 years of hands-on application security engineering experience securing production systems.
  • Understanding of developer experience and workflows for shipping products.
  • Expertise in at least two of Python, Java, Go, and JavaScript/TypeScript, with the ability to review code across multiple languages.
  • Knowledge of SAST/DAST solutions, vulnerability-management platforms, security-testing frameworks, and DevSecOps practices.
  • Strong communication skills for translating security concepts into clear recommendations.
  • Builder's mindset focused on automation, scalability, and enabling engineering teams.

Compensation and Benefits

  • Annual salary range: $131,800–$257,700.
  • Competitive compensation, company stock options, and 401(k).
  • Paid time off and company holidays.
  • Medical, dental, and vision coverage.
  • Paid parental leave.
  • Fertility and family-planning support.
  • Flexible spending and health savings account options.
  • Wellness and learning stipends.
  • Company and team off-sites.

Skills

Application Security, Threat Modeling, SAST, DAST, CI/CD, Secure Coding, Python, Java, Go, JavaScript, TypeScript, Penetration Testing, DevSecOps, Llm Security, Vulnerability Management

Mercor

Mercor

San Francisco, CA
Security Engineer, Application Security
$130k+/yrOn-site5+ YOESecurity Engineering

Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.

Coinbase

Coinbase

United States

Analyst, Privacy
$135k+/yrRemote3+ YOESecurity Engineering

Own Coinbase’s privacy incident management program, leading investigations, response coordination, remediation, retrospectives, and process improvements. The role requires 3+ years in privacy, security, incident response, or technology risk, plus SQL, Python, automation, and privacy regulatory knowledge.

OpenAI

OpenAI

San Francisco, CA
Protective Intelligence & Threat Analyst
$126k+/yrHybrid5+ YOESecurity Engineering

Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.

Applied Intuition

Applied Intuition

Sunnyvale, CA

System Safety Engineer, Mining/Industrial
$125k+/yrOn-site5+ YOESecurity Engineering

Develops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.

Pinterest

Pinterest

United States

Security GRC Analyst
$124k+/yrRemote4+ YOESecurity Engineering

The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.