Owns application security across code, APIs, services, identity systems, and AI-specific surfaces. The role requires 6+ years of hands-on security engineering experience, AppSec program-building expertise, modern application-stack knowledge, and AWS proficiency.
230k – 330k/yr
On-site6+ YOESecurity Engineering
About the role
Responsibilities
Execute application security end to end by threat-modeling features and services and driving remediation of significant risks.
Secure the application layer against injection, broken authentication and authorization, and insecure APIs.
Build and run a secure SDLC, including code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.
Harden authentication, authorization, and session/identity handling across the product.
Secure AI-specific application surfaces, including model and inference endpoints, prompt and input handling, and emerging generative-AI vulnerabilities.
Partner with product and platform engineering to design security in early and raise the security bar across the codebase.
Set standards for how engineering reasons about and ships secure code.
Requirements
6+ years in security engineering with deep, hands-on application-security expertise.
Strong command of vulnerability classes that cause incidents and how to eliminate them at the source through code, API, and authorization design.
Experience building AppSec practices and secure-SDLC tooling from the ground up.
Fluency with modern application stacks and AWS.
Ability to collaborate closely with engineers without becoming a blocker.
Ability to write and ship production-quality code, not only review it.
Curiosity about emerging AI/LLM threat classes and defensive strategies.
Nice to Have
Experience with consumer products at scale.
Secure-by-design experience on generative-AI or ML product surfaces.
Experience as an early security hire.
Compensation & Benefits
Annual compensation of $230,000 to $330,000.
Company equity package.
401(k) with 3% employer match and Roth 401(k).
Medical, dental, and vision insurance, with PPO, HSA, and FSA options.
Owns detection engineering and incident response across cloud infrastructure, building telemetry, high-signal detections, response playbooks, and on-call practices. The role requires 6+ years of detection and response experience, strong AWS expertise, and interest in emerging AI/ML threats.
230k – 330k/yrOn-site7+ YOESecurity Engineering
Senior Staff Security Engineer - Network Security
GustoSan Francisco, CA
Leads edge and network security strategy, owning Cloudflare WAF, DDoS protection, Zero Trust, and AWS perimeter controls. Partners with teams to implement layered defenses, policy-as-code, detections, and AI-assisted automations. Requires 10+ years experience with deep Cloudflare and network expertise.
230k – 270k/yrHybrid10+ YOESecurity Engineering
Staff Security Engineer - SecOps & Threats
6senseUnited States
Leads SecOps and threat response, including incident handling, forensics, automation building, and threat exercises. Requires 5+ years in Security Operations, automation experience, and familiarity with security tools like SIEM, SOAR, and AWS.
231k – 266k/yrRemote5+ YOESecurity Engineering
Staff Product Security Engineer
DatabricksCalifornia
Staff Security Software Engineer leading architecture, standards, and development of AI security tooling, threat detection, and red-teaming platforms at Databricks. Requires 7-10 years security engineering experience, expert Python skills, and deep AI/ML security expertise.
231k – 398k/yrRemote7+ YOESecurity Engineering
Staff Application Security Engineer
AbridgeSan Francisco, CA
Lead application security initiatives as a technical leader on a new security team. Drive threat modeling, secure SDLC, code reviews, vulnerability management, and AI security for a healthcare AI platform.