Skip to content

Application Security Engineer

The Application Security Engineer will lead an engineering-driven vulnerability management program, validating and prioritizing findings, automating workflows, and partnering with development teams on remediation. The role requires strong application security fundamentals, coding ability, and experience with modern scanning, cloud, container, and CI/CD environments.

About the job

Responsibilities

  • Own and continuously improve vulnerability management across applications, software dependencies, containers, operating systems, cloud infrastructure, and externally exposed services.
  • Use AI agents and advanced security models to augment vulnerability discovery, code analysis, adversarial testing, prioritization, and remediation.
  • Analyze vulnerabilities based on exploitability, exposure, affected assets, mitigations, and business impact—not scanner severity alone.
  • Partner with engineering, infrastructure, and IT teams to triage findings, determine remediation, and meet risk-based SLAs.
  • Build automation for vulnerability ingestion, deduplication, enrichment, prioritization, assignment, remediation tracking, and reporting.
  • Identify systemic vulnerability patterns and address root causes.
  • Operate and improve SAST, SCA, secrets detection, container scanning, infrastructure scanning, and external attack-surface monitoring.
  • Validate findings through technical investigation and hands-on testing; distinguish exploitable vulnerabilities from false positives and low-risk findings.
  • Perform targeted application security reviews and testing for high-risk services and features.
  • Integrate security controls into CI/CD and developer workflows.
  • Develop metrics and reporting for vulnerability exposure, remediation performance, recurring vulnerability classes, and security risk.
  • Evaluate new security technologies and support incident response for actively exploited vulnerabilities.

Requirements

  • Strong application security or product security fundamentals and hands-on vulnerability management experience.
  • Knowledge of vulnerability classes and exploitation techniques across web applications, APIs, authentication systems, cloud services, containers, and software supply chains.
  • Ability to read and reason about code and collaborate with software engineers on remediation.
  • Experience with vulnerability scanning and application security technologies such as SAST, SCA, DAST, secrets scanning, container scanning, or CSPM.
  • Understanding of CVSS, exploitability, asset criticality, internet exposure, compensating controls, and threat intelligence.
  • Experience manually investigating security findings.
  • Ability to automate security workflows using Python, Go, or similar languages.
  • Experience integrating security tooling into CI/CD and software development workflows.
  • Comfort with Linux, Git, containers, and cloud environments.
  • Ability to communicate security risk clearly to security specialists and engineering teams.
  • Automation-first mindset and focus on scalable solutions.

Nice-to-haves

  • Application security or security engineering experience.
  • Experience securing AI/ML platforms, inference services, or large-scale compute infrastructure.
  • Experience building or operating vulnerability management programs at scale.
  • AWS, Kubernetes, Docker, and cloud-native experience.
  • Software supply-chain security and dependency management.
  • GitHub and CI/CD security.
  • Threat modeling and secure design reviews.
  • Penetration testing or offensive security.
  • External attack-surface management.
  • Vulnerability research or exploit validation.
  • Security data pipelines, APIs, and workflow automation.
  • Experience using LLMs, AI agents, or AI-assisted security tooling for vulnerability research, code analysis, penetration testing, or remediation.

Skills

Vulnerability Management, SAST, Sca, DAST, Cspm, Python, Go, Linux, Git, Containers, AWS, Kubernetes, Docker, CI/CD, Threat Modeling

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.