Skip to content
BioRenderBioRender

Senior Application Security Engineer

The Senior Application Security Engineer builds security tooling and production code, embeds secure-by-design practices, leads threat modeling, and protects AI-integrated features. The role requires strong web application security, software engineering, CI/CD security, AWS, and infrastructure-as-code experience.

About the job

Responsibilities

Hands-on engineering and codebase contribution

  • Contribute production-quality code directly to the application using Node.js and React, and to infrastructure using Python and Terraform.
  • Build and maintain security and CI/CD tooling, keeping the secure path the default path.
  • Review RFCs and design documents for security and pair with engineers to resolve issues at the source.

Architecture, design, and Secure SDLC

  • Define secure-by-design patterns and standards for authentication, authorization, and API security.
  • Lead threat modeling and turn models into shipped controls.
  • Own and evolve Secure SDLC and CI/CD security integrations, including SAST, DAST, SCA, and secrets scanning.

AI-native security and automation

  • Use AI coding assistants and agentic tooling for code review, triage, and tooling development.
  • Secure AI-integrated product features against prompt injection, data leakage, and over-scoped tool, token, and data access.
  • Automate recurring security work so the team scales through leverage.

Web and product security

  • Perform penetration testing and Node.js/React code reviews using OWASP methodology.
  • Identify and remediate application security vulnerabilities through SAST, DAST, and HackerOne.
  • Own the bug bounty program, including issue evaluation, reproduction, and resolution through shipped fixes.

Requirements

  • Demonstrable software engineering ability, including fluency reading code and writing production-quality code in real codebases.
  • Experience with Node.js and React; Python experience is a plus.
  • Fluency with AI development tools, including AI coding assistants and agentic workflows.
  • Expertise in web application security and secure-coding best practices.
  • Experience integrating and maintaining SAST/DAST systems within CI/CD and with Secure Software Development Lifecycles.
  • Hands-on experience securing cloud workloads on AWS and working with infrastructure as code such as Terraform.
  • Threat-modeling experience and knowledge of common code and network vulnerabilities, their impact, and remediation.
  • Applied knowledge of cryptography, PKI, and TLS and their practical implementation.

Nice to have

  • Experience hardening LLM-integrated or AI-powered features in production.
  • Experience operating a bug bounty program, such as HackerOne.
  • Contributions to SOC 2 control design and audit readiness from the engineering side.
  • OSCP, OSWE, or AWS Security Specialty certification.
  • Familiarity with Cloudflare.

Skills

Node.js, React, Python, Terraform, AWS, Cloudflare, SAST, DAST, Sca, CI/CD, Owasp, Hackerone, Cryptography, Pki, Tls

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Coalition Security

Coalition Security

United States
Senior Security Support Analyst
$94k+/yrRemote5+ YOESecurity Engineering

Investigates cyber incidents and insurance claims, assesses security controls, and advises customers and security leaders on prioritized risk improvements. The role requires 2–4 years of security experience, strong network threat knowledge, and familiarity with major security and compliance frameworks.

OpenAI

OpenAI

Toronto, Canada

Cyber Operations Strategist, Critical Harm Operations
CA$140k+/yrRemote8+ YOESecurity Engineering

Senior individual contributor responsible for improving cyber operations, resolving complex dual-use safety decisions, and building scalable reviewer, quality, vendor, and automation systems. Requires 8+ years of hands-on cybersecurity experience and strong operational judgment.

Instacart

Instacart

United States
Senior Detection Engineer II
$192k+/yrRemote6+ YOESecurity Engineering

Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.

GitLab

GitLab

United States
Senior Manager, Product Security Engineering
$168k+/yrRemote5+ YOESecurity Engineering

Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.