Senior/Staff Engineer, Application & Product Security
Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.
About the job
Responsibilities
- Champion a secure-by-default culture by building defense in depth into frameworks, architecture, and everyday processes.
- Develop security requirements and work directly with teams to integrate them into applications and services.
- Review source code to develop a deep understanding of products and identify security risks.
- Drive the product security roadmap with product, engineering, DevOps, and security teams.
- Design solutions to resolve and mitigate vulnerabilities and risk.
- Research relevant threats and attack methods.
- Conduct security risk assessments, hands-on penetration testing, and threat modeling.
- Turn findings into secure-coding education for engineers.
Requirements
- 6+ years of experience in application or product security.
- Strong coding ability to automate tedious work and build security frameworks or services.
- Hands-on experience with microservice architectures.
- Ability to collaborate across security, engineering, product, DevOps, and services teams.
- Risk prioritization based on real-world impact rather than raw vulnerability counts.
- Deep experience working directly in a codebase, beyond relying only on SAST, DAST, and SBOM tooling.
- Ability to understand products and work effectively with product managers and service teams.
Compensation & Benefits
- Base compensation for fully remote commitment: $182,000–$240,000 USD annually.
- Base compensation for hybrid commitment: $217,000–$288,000 USD annually.
- Comprehensive medical, dental, vision, life, and disability coverage.
- No-cost access to therapy through the Grow platform for US employees.
- Retirement savings programs and equity opportunities.
- Flexible time off, paid holidays, and company-wide winter break.
- Up to 18 weeks of paid parental leave and a new-child stipend.
- Weekly flexible time for self-care.
- Wellness and development stipend.
- Pre-tax commuter benefits for hub employees.
- Home-office and meal benefits.
- Additional wellbeing benefits, virtual care, pet insurance discounts, and global travel assistance.
Skills
Application Security, Product Security, Microservices, Threat Modeling, Penetration Testing, Source Code Review, Secure Coding, SAST, DAST, Sbom, CI/CD, Security Risk Assessment
Similar jobs
Security Engineering jobsLeads security architecture, assessments, automation, and security-by-design practices for the Walrus team and broader ecosystem. The role requires 8+ years of security engineering experience, broad technical expertise, and Staff-level leadership.
Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.
Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.