Skip to content

Application Security Engineer

Application Security Engineer prevents and eliminates software vulnerabilities by consulting with product teams, creating analysis rules, providing developer education, and building security tools. Requires 3+ years experience in secure software design.

165k – 200kSan Francisco, CASecurity EngineeringHybrid3+ YOE

About the role

What You'll Achieve

  • As an early member of Notion’s Application Security team, you will have a large input in defining the direction and goals of the program.
  • Make the secure path the easy path for product teams by providing design guidance and finding solutions that eliminate classes of vulnerabilities.
  • Create static and dynamic analysis rules that detect weaknesses in our codebase.
  • Provide developers guidance and education on security and privacy best practices that prevent the authoring of vulnerabilities.
  • Participate in and drive mitigation strategies during AppSec related incident responses.
  • Build and maintain tools that prevent vulnerabilities or automate remediation.

Skills You'll Need to Bring

  • Security Architecture expertise: You have at least 3+ years of experience working with product teams to design and/or build secure software.
  • Thoughtful problem-solving: For you, problem-solving starts with a clear and accurate understanding of the context. You can decompose tricky problems and work towards a clean solution, by yourself or with teammates.
  • Ability to advocate for and lead cross functional projects: You regularly advocate for security hardening projects that you then lead by partnered with product engineering teams.
  • Pragmatic and business-oriented: You care about business impact and prioritize projects accordingly.
  • Empathetic communication: You communicate nuanced ideas clearly.
  • Startup mentality: You are comfortable navigating the fast moving, unstructured nature of a hyper-growth startup.
  • You don’t need to be an AI expert, but you’re curious and willing to adopt AI tools to work smarter.

Nice to Haves

  • Participation in bug bounty programs or capture the flag exercises
  • Published reports of vulnerabilities you have found or AppSec related blog posts
  • Involvement in local or regional security user groups or conferences

Compensation

For roles based in San Francisco and New York, the estimated base salary range is $165,000 - $200,000 per year.

Skills

Application SecurityStatic AnalysisDynamic AnalysisSecurity ArchitectureSecure CodingThreat ModelingBug BountyVulnerability RemediationSecurity ToolsPrivacy Best Practices

Risk Automation Engineer

The Risk Automation Engineer will design, build, and operate secure, agentic automation pipelines to manage risk and vendor lifecycles. This role focuses on eliminating manual GRC processes through AI-driven workflows and real-time risk posture visibility.

165k – 185kUnited StatesSecurity EngineeringRemote5+ YOEGoAWS

Security Software Engineer

Software engineer focused on security and privacy, improving Tailscale's security through feature development, audits, threat modeling, and spending 50% time writing code. Requires proficiency in Go or similar, security experience, and deep knowledge of vulnerabilities and cryptography.

163k – 204kUnited StatesSecurity EngineeringRemoteGoLinux

Security Infrastructure Engineer

Builds security controls across cloud, Kubernetes, networks, and CI/CD for Tailscale. Audits infrastructure, implements security features in Go/Terraform, and provides threat modeling expertise. Requires cloud security and infrastructure experience.

163k – 204kUnited StatesSecurity EngineeringRemoteGoAWS

Fraud Researcher

Leads complex fraud investigations using Plaid's financial network data, reconstructs attacker behaviors, and collaborates with Data Science, ML, and Product teams to enhance detection models and fraud prevention products. Requires 3+ years applied fraud experience and strong analytical skills.

162k – 244kNew York, NY +2Security EngineeringHybrid3+ YOESQLPython

GRC Program Manager, US Government Compliance

Leads US government compliance programs, driving FedRAMP and agency ATOs for OpenAI products. Collaborates with engineers on security controls, documentation, and audits in highly regulated environments. Requires 5+ years compliance experience and deep USG framework knowledge.

162k – 310kWashington, DCSecurity EngineeringHybrid5+ YOERmfAWS