# Security Engineer, Application Security

**Company:** [Writer](https://hotfix.jobs/companies/writer)
**Location:** New York, NY, Seattle, WA, San Francisco, CA
**Role:** Security Engineering
**Salary:** $132k – $258k/yr
**Experience:** 4+ years
**Skills:** Application Security, Threat Modeling, SAST, DAST, CI/CD, Secure Coding, Python, Java, Go, JavaScript, TypeScript, Penetration Testing, DevSecOps, Llm Security, Vulnerability Management
**Posted:** 2026-09-04

> Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.

## Job Description

## Responsibilities
- Conduct threat modeling with product teams and design secure architectures for new features.
- Own and evolve the application security program, including SAST/DAST scanning in CI/CD pipelines, security code reviews, and vulnerability-detection automation.
- Establish secure coding standards and create reusable security patterns and libraries.
- Design and recommend security features and products for customer environments.
- Integrate AI agents to improve security-team and engineering velocity while minimizing risk.
- Lead security assessments and penetration testing of applications, AI services, and APIs; coordinate remediation at scale.
- Design and implement controls for data pipelines, model-training environments, and customer-facing AI agents.
- Research LLM and generative-AI attack vectors and build defenses against emerging threats.

## Requirements
- At least 4 years of hands-on application security engineering experience securing production systems.
- Understanding of developer experience and workflows for shipping products.
- Expertise in at least two of Python, Java, Go, and JavaScript/TypeScript, with the ability to review code across multiple languages.
- Knowledge of SAST/DAST solutions, vulnerability-management platforms, security-testing frameworks, and DevSecOps practices.
- Strong communication skills for translating security concepts into clear recommendations.
- Builder's mindset focused on automation, scalability, and enabling engineering teams.

## Compensation and Benefits
- Annual salary range: $131,800–$257,700.
- Competitive compensation, company stock options, and 401(k).
- Paid time off and company holidays.
- Medical, dental, and vision coverage.
- Paid parental leave.
- Fertility and family-planning support.
- Flexible spending and health savings account options.
- Wellness and learning stipends.
- Company and team off-sites.

## Similar jobs

- [Security Engineer, Application Security](https://hotfix.jobs/jobs/f2d0e34d-91a7-4864-8672-e4a6901e3ca0) - Mercor - San Francisco, CA - $130k – $500k/yr
- [Analyst, Privacy](https://hotfix.jobs/jobs/a897f8bc-44ea-42dd-bee6-ca5768c8084e) - Coinbase - Remote - $135k – $159k/yr
- [Protective Intelligence & Threat Analyst](https://hotfix.jobs/jobs/19e4e635-ad0e-474f-85ee-147d674f6395) - OpenAI - San Francisco, CA - $126k – $225k/yr
- [System Safety Engineer, Mining/Industrial](https://hotfix.jobs/jobs/644fb8c1-f6aa-4519-96c9-d8abfb23da9f) - Applied Intuition - Sunnyvale, CA - $125k – $225k/yr
- [Security GRC Analyst](https://hotfix.jobs/jobs/e2503f84-7d16-49f3-9f64-65e03e688c69) - Pinterest - Remote - $124k – $255k/yr

**Apply:** https://hotfix.jobs/jobs/902bb48a-e5f1-479e-b144-9fc1b0f431e0
**Canonical:** https://hotfix.jobs/jobs/902bb48a-e5f1-479e-b144-9fc1b0f431e0