Skip to content
CensysCensysSan Francisco, CA

Staff Application Security Engineer

Staff Application Security Engineer owning the AppSec/DevSecOps program at Censys. Design and implement secure SDLC practices, DevSecOps tooling in Kubernetes/GCP (incl. AI/ML pipelines), CI/CD security integrations, compliance controls, and provide technical leadership/mentorship to engineering teams. Requires 10+ years security engineering experience.

172k – 233k/yr
Remote10+ YOESecurity Engineering

About the role

What You’ll Do

  • Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates
  • Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads
  • Lead the integration of security into CI/CD pipelines — code scanning, secret detection, software composition analysis, and infrastructure policy enforcement — partnering with engineering teams to adopt them without friction
  • Deliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organization
  • Set the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance tracking
  • Partner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracy
  • Provide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teams
  • Participate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readiness

What You’ll Bring

  • 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teams
  • Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane)
  • Strong experience with Application Security tooling — dependency scanning, static analysis, and policy enforcement — integrated into CI/CD pipelines such as GitHub Actions and ArgoCD, and the ability to bridge engineering practices with Security Operations
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs), and familiarity with frameworks like MITRE ATT&CK
  • Strong grasp of cloud services (GCP preferred), especially securing data pipelines, model hosting endpoints, and related infrastructure
  • Proficiency with Infrastructure-as-Code (Terraform, Crossplane, or similar) and security scanning for cloud resources
  • Proficiency with scripting and automation (e.g., Python, Bash)
  • The ability to thoughtfully participate in technical discussions and drive towards data-driven decisions amidst ambiguity and competing priorities
  • Strong communication skills and empathy for developer needs, with a demonstrated ability to embed secure practices without creating friction

What Sets You Apart

  • Experience building or scaling an AppSec or DevSecOps program from early maturity, including establishing paved roads and measuring adoption
  • Familiarity with commercial security platforms such as Orca Security (CNAPP/cloud security posture) and Aikido Security (application security scanning) is a plus
  • Experience securing ML toolchains (e.g., TensorFlow, PyTorch) and familiarity with AI-specific threats such as data leakage, model inversion, prompt injection, and adversarial inputs
  • Hands-on experience integrating and managing Web Application Firewalls (WAF), anti-DDoS systems, and edge protection technologies
  • Familiarity with monitoring and observability systems (e.g., Prometheus, Grafana, OpenTelemetry) with a focus on detecting security anomalies
  • Familiarity with AI governance and compliance standards (e.g., EU AI Act, NIST AI Risk Management Framework)
  • Strong interest in harnessing AI and LLM tools as a force multiplier — using them to code smarter, iterate faster, boosting productivity and enhancing product capabilities

Compensation

For high cost of living areas (San Francisco Bay, New York City, and Seattle), the expected salary range for this position is $198,000 – $233,000, plus bonus eligibility and equity. For all other US locations, the expected salary range for this position is $172,000 – $216,000, plus bonus eligibility and equity.

Skills

KubernetesGCPTerraformPythonDevSecOpsApplication SecurityCI/CDmitre att&ckSOC 2iso27001TensorFlowPyTorchwafPrometheus
Earnin

Staff Risk Analyst

EarninUnited States

Owns full fraud risk management lifecycle including strategy, policy design, cross-functional leadership, and analytics in fintech. Requires 7+ years experience, SQL/Python, fraud platforms, and deep credit card knowledge.

170k – 210k/yrRemote7+ YOESecurity Engineering
Ironclad

Staff Application Security Engineer

IroncladSan Francisco, CA

Leads application security assessments, vulnerability testing, and secure coding practices for a SaaS platform. Requires 3+ years in app sec or software dev, proficiency in TypeScript/JavaScript, security tools like Burp Suite, and cloud experience.

170k – 190k/yrHybridSecurity Engineering
ezCater

Staff GRC Engineer

ezCaterUnited States

Senior individual contributor leading GRC program maturity, control automation, data security governance, and AI governance for a SaaS food tech platform. Requires 8+ years in security compliance with strong automation and cross-functional influence skills.

165k – 210k/yrRemote8+ YOESecurity Engineering
Huntress

Staff Cloud Security Engineer

HuntressUnited States

Designs and implements secure cloud architectures for AWS and Azure, integrates security into DevSecOps pipelines, manages vulnerabilities, and leads threat detection/response for a B2B SaaS cybersecurity platform. Requires deep cloud expertise and SaaS production security experience.

165k – 193k/yrRemoteSecurity Engineering
Okta

Staff Product Security Engineer

OktaSan Francisco, CA

Staff Product Security Engineer focused on offensive research and security assessments of agentic AI systems, LLM-integrated platforms, and building reusable security tooling. Requires 7+ years in application/offensive/AI security and demonstrated experience finding vulnerabilities in agentic architectures.

180k – 248k/yrHybrid7+ YOESecurity Engineering