Skip to content

Application Security Engineer

Application Security Engineer conducts secure code reviews, threat modeling, and automates security tooling with AI in CI/CD pipelines to protect patient data systems. Requires 5+ years app sec experience, coding proficiency in modern languages, and cloud/container security knowledge.

205k – 275kSouth San Francisco, CASecurity EngineeringHybrid5+ YOE

About the role

Responsibilities

  • Perform secure code reviews, threat modeling, and security design reviews for new features and services.
  • Use AI to automate tooling like SAST, DAST, SCA, secret scanning, and container scanning tools across our CI/CD pipelines.
  • Use AI to triage and validate vulnerability findings from automated tools, penetration tests, and bug bounty submissions. Track remediation to closure.
  • Work directly with engineering squads to fix security issues, helping developers understand the “why” and the fix.
  • Support third-party penetration tests: scoping, coordination, triage, and follow-through on results.
  • Contribute to developer security guides and training grounded in our actual codebase and stack.
  • Help maintain and improve our vulnerability management workflows and tracking using AI.
  • Support compliance work related to HIPAA and SOC 2 where it touches application and data security.
  • Stay current on the threat landscape and flag emerging risks relevant to our technology and industry.

Requirements

Must-haves

  • 5+ years of experience in application security. Technical Skills
  • Written production code and can read, review, and critique code in at least one modern language (Python, Go, Java, TypeScript, etc.).
  • Solid working knowledge of common vulnerability classes (OWASP Top 10, injection attacks, auth flaws, insecure deserialization, etc.) and how to fix them.
  • Hands-on experience with threat modeling and secure code review against real systems.
  • Experience working with security tooling in CI/CD pipelines (SAST, SCA, secret scanning, GitHub Actions, etc.).
  • Familiarity with cloud environments (AWS) and container/Kubernetes basics from a security angle.
  • Working understanding of auth standards (OAuth 2.0, OIDC, SAML) and API security concepts (REST, GraphQL).

How You Work

  • Collaborative, prefer helping developers fix issues directly.
  • Communicate clearly to engineers and product managers.
  • Organized to juggle multiple findings across teams.
  • Comfortable with ambiguity in fast-moving environment.
  • Care about mission protecting patient data.

Nice-to-haves

  • Experience in healthcare or health-tech; familiarity with HIPAA Security Rule requirements.
  • Exposure to compliance frameworks like SOC 2 Type II, HIPAA, or HITRUST.
  • Experience at a company where you’ve worn multiple hats.
  • Relevant certifications (OSCP, CSSLP, CEH).

Compensation

  • Salary range: $205,000-$275,000 + Equity.
  • Flexible PTO, health/dental/vision coverage, HSA contributions, parental leave, life insurance, home office stipend, cell/internet reimbursement, 401(k).

Skills

PythonGoJavaTypeScriptOwasp Top 10SASTDASTScaKubernetesAWSOauth 2.0OIDCSAMLRestGraphQL

Security Engineer, Product Security

Security Engineer conducts code reviews, implements secure CI/CD pipelines, performs SAST/DAST testing, and secures AWS infrastructure using Terraform. Requires expertise in TypeScript, Python, NodeJS, and product security best practices to mitigate vulnerabilities in AI/ML products.

206k – 297kNew York, NY +2Security EngineeringOn-siteAWSSAST

Model Policy Manager

Defines and maintains policies for AI model behavior in high-risk domains like agentic systems and user safety. Collaborates with research, engineering, and product teams to operationalize policies into measurable safeguards using empirical data and red-teaming.

207k – 295kSan Francisco, CASecurity EngineeringHybridAi SafetyRed-Teaming

Model Policy, Frontier Cyber Risk

Develops and maintains AI model policies for high-risk cybersecurity domains, translating threat models into behavioral specifications, evaluations, and mitigations. Collaborates with research, engineering, and safety teams to ensure technically grounded, enforceable safeguards against dual-use risks.

207k – 295kSan Francisco, CASecurity EngineeringHybridRed-TeamingCloud Security

Platform Engineer, Security

Lead application security strategy and implementation for Decagon's conversational AI platform. Partner with engineering teams to build security into AI-powered applications and establish testing programs.

200k – 330kSan Francisco, CASecurity EngineeringOn-site3+ YOESASTDAST

Security Engineer - Vuln Management (Infra)

Mid-level Infrastructure Vulnerability Management Engineer responsible for cloud security posture, IaC scanning, container vulnerability management, and compliance tracking across multi-cloud environments. Requires 5+ years in cloud security/DevSecOps with deep GCP expertise.

210k – 270kFoster City, CASecurity EngineeringHybrid5+ YOEGCPAWS