Skip to content
SunoSunoBoston, MA

Senior / Staff Application Security Engineer

Owns application security across code, APIs, services, identity systems, and AI-specific surfaces. The role requires 6+ years of hands-on security engineering experience, AppSec program-building expertise, modern application-stack knowledge, and AWS proficiency.

230k – 330k/yr
On-site6+ YOESecurity Engineering

About the role

Responsibilities

  • Execute application security end to end by threat-modeling features and services and driving remediation of significant risks.
  • Secure the application layer against injection, broken authentication and authorization, and insecure APIs.
  • Build and run a secure SDLC, including code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.
  • Harden authentication, authorization, and session/identity handling across the product.
  • Secure AI-specific application surfaces, including model and inference endpoints, prompt and input handling, and emerging generative-AI vulnerabilities.
  • Partner with product and platform engineering to design security in early and raise the security bar across the codebase.
  • Set standards for how engineering reasons about and ships secure code.

Requirements

  • 6+ years in security engineering with deep, hands-on application-security expertise.
  • Strong command of vulnerability classes that cause incidents and how to eliminate them at the source through code, API, and authorization design.
  • Experience building AppSec practices and secure-SDLC tooling from the ground up.
  • Fluency with modern application stacks and AWS.
  • Ability to collaborate closely with engineers without becoming a blocker.
  • Ability to write and ship production-quality code, not only review it.
  • Curiosity about emerging AI/LLM threat classes and defensive strategies.

Nice to Have

  • Experience with consumer products at scale.
  • Secure-by-design experience on generative-AI or ML product surfaces.
  • Experience as an early security hire.

Compensation & Benefits

  • Annual compensation of $230,000 to $330,000.
  • Company equity package.
  • 401(k) with 3% employer match and Roth 401(k).
  • Medical, dental, and vision insurance, with PPO, HSA, and FSA options.
  • 11 paid holidays, unlimited PTO, and sick time.
  • 16 weeks of paid parental leave.
  • Creative education stipend.
  • Generous commuter allowance.
  • In-office lunch five days per week.
  • Onsite work at one of the company’s offices.

Skills

Application SecurityThreat Modelingsecure sdlcSASTDASTdependency securitysupply chain securitysecrets managementAuthenticationauthorizationAWSai securityllm securityapi securityproduction code
Suno

Staff Detection & Response Engineer

SunoBoston, MA +3

Owns detection engineering and incident response across cloud infrastructure, building telemetry, high-signal detections, response playbooks, and on-call practices. The role requires 6+ years of detection and response experience, strong AWS expertise, and interest in emerging AI/ML threats.

230k – 330k/yrOn-site7+ YOESecurity Engineering
Gusto

Senior Staff Security Engineer - Network Security

GustoSan Francisco, CA

Leads edge and network security strategy, owning Cloudflare WAF, DDoS protection, Zero Trust, and AWS perimeter controls. Partners with teams to implement layered defenses, policy-as-code, detections, and AI-assisted automations. Requires 10+ years experience with deep Cloudflare and network expertise.

230k – 270k/yrHybrid10+ YOESecurity Engineering
6sense

Staff Security Engineer - SecOps & Threats

6senseUnited States

Leads SecOps and threat response, including incident handling, forensics, automation building, and threat exercises. Requires 5+ years in Security Operations, automation experience, and familiarity with security tools like SIEM, SOAR, and AWS.

231k – 266k/yrRemote5+ YOESecurity Engineering
Databricks

Staff Product Security Engineer

DatabricksCalifornia

Staff Security Software Engineer leading architecture, standards, and development of AI security tooling, threat detection, and red-teaming platforms at Databricks. Requires 7-10 years security engineering experience, expert Python skills, and deep AI/ML security expertise.

231k – 398k/yrRemote7+ YOESecurity Engineering
Abridge

Staff Application Security Engineer

AbridgeSan Francisco, CA

Lead application security initiatives as a technical leader on a new security team. Drive threat modeling, secure SDLC, code reviews, vulnerability management, and AI security for a healthcare AI platform.

228k – 290k/yrHybrid10+ YOESecurity Engineering