# Application Security Engineer

**Company:** [Cerebras Systems](https://hotfix.jobs/companies/cerebras-systems)
**Location:** Sunnyvale, CA
**Role:** Security Engineering
**Skills:** Vulnerability Management, SAST, Sca, DAST, Cspm, Python, Go, Linux, Git, Containers, AWS, Kubernetes, Docker, CI/CD, Threat Modeling
**Posted:** 2026-09-02

> The Application Security Engineer will lead an engineering-driven vulnerability management program, validating and prioritizing findings, automating workflows, and partnering with development teams on remediation. The role requires strong application security fundamentals, coding ability, and experience with modern scanning, cloud, container, and CI/CD environments.

## Job Description

## Responsibilities
- Own and continuously improve vulnerability management across applications, software dependencies, containers, operating systems, cloud infrastructure, and externally exposed services.
- Use AI agents and advanced security models to augment vulnerability discovery, code analysis, adversarial testing, prioritization, and remediation.
- Analyze vulnerabilities based on exploitability, exposure, affected assets, mitigations, and business impact—not scanner severity alone.
- Partner with engineering, infrastructure, and IT teams to triage findings, determine remediation, and meet risk-based SLAs.
- Build automation for vulnerability ingestion, deduplication, enrichment, prioritization, assignment, remediation tracking, and reporting.
- Identify systemic vulnerability patterns and address root causes.
- Operate and improve SAST, SCA, secrets detection, container scanning, infrastructure scanning, and external attack-surface monitoring.
- Validate findings through technical investigation and hands-on testing; distinguish exploitable vulnerabilities from false positives and low-risk findings.
- Perform targeted application security reviews and testing for high-risk services and features.
- Integrate security controls into CI/CD and developer workflows.
- Develop metrics and reporting for vulnerability exposure, remediation performance, recurring vulnerability classes, and security risk.
- Evaluate new security technologies and support incident response for actively exploited vulnerabilities.

## Requirements
- Strong application security or product security fundamentals and hands-on vulnerability management experience.
- Knowledge of vulnerability classes and exploitation techniques across web applications, APIs, authentication systems, cloud services, containers, and software supply chains.
- Ability to read and reason about code and collaborate with software engineers on remediation.
- Experience with vulnerability scanning and application security technologies such as SAST, SCA, DAST, secrets scanning, container scanning, or CSPM.
- Understanding of CVSS, exploitability, asset criticality, internet exposure, compensating controls, and threat intelligence.
- Experience manually investigating security findings.
- Ability to automate security workflows using Python, Go, or similar languages.
- Experience integrating security tooling into CI/CD and software development workflows.
- Comfort with Linux, Git, containers, and cloud environments.
- Ability to communicate security risk clearly to security specialists and engineering teams.
- Automation-first mindset and focus on scalable solutions.

## Nice-to-haves
- Application security or security engineering experience.
- Experience securing AI/ML platforms, inference services, or large-scale compute infrastructure.
- Experience building or operating vulnerability management programs at scale.
- AWS, Kubernetes, Docker, and cloud-native experience.
- Software supply-chain security and dependency management.
- GitHub and CI/CD security.
- Threat modeling and secure design reviews.
- Penetration testing or offensive security.
- External attack-surface management.
- Vulnerability research or exploit validation.
- Security data pipelines, APIs, and workflow automation.
- Experience using LLMs, AI agents, or AI-assisted security tooling for vulnerability research, code analysis, penetration testing, or remediation.

## Similar jobs

- [Security Engineer, Threat Intelligence](https://hotfix.jobs/jobs/a9d333c0-2242-416f-a470-d3a19f982046) - Fluidstack - New York, NY - $220k – $280k/yr
- [Security Scientist](https://hotfix.jobs/jobs/36a4a0c9-f833-41fb-bd29-ad40c4d5050f) - Figma - Remote - $140k – $348k/yr
- [Security Engineer](https://hotfix.jobs/jobs/061a2617-4d6a-4cf3-96a0-ad832100d55f) - hud - San Francisco, CA
- [Abuse Research Engineer](https://hotfix.jobs/jobs/2f1effd6-b955-48c7-9d30-3d0aed220264) - Stripe - Remote
- [Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e5c4fc22-2c3a-4334-8eae-e8ab5bcf2a8a) - Anthropic - San Francisco, CA - $300k – $320k/yr

**Apply:** https://hotfix.jobs/jobs/e9afbbd3-0c88-4a57-a0e5-2cbe81dd220c
**Canonical:** https://hotfix.jobs/jobs/e9afbbd3-0c88-4a57-a0e5-2cbe81dd220c