Security Engineer, Application Security
Conduct low-level code security assessments, architecture reviews, and threat modeling for client applications. Build custom security tools bridging vulnerability research and application security. Requires manual code review, binary analysis, and programming proficiency in multiple languages.
What You’ll Achieve
Security Assessment: Conduct comprehensive low-level code security assessments across applications, examining vulnerabilities in system services, access control implementation, inter-process communication, and platform security controls while developing mitigation strategies.
Security Tool Development: Design and implement custom security tools for automated vulnerability detection, focusing on both application-specific and general security testing needs to bridge the gap between vulnerability research and application security.
Architecture Review: Perform detailed architecture reviews and threat modeling of complex software systems and cloud environments, identifying potential security weaknesses in areas such as data flows, authentication mechanisms, and API security while providing remediation guidance.
Client Engagement: Work directly with industry-leading teams to review their application infrastructure and architecture, helping secure their environments through deep technical analysis and recommendations.
Research & Innovation: Contribute to the advancement of application security, developing new methodologies and tools while staying up to date with the latest security developments in both traditional and emerging technology ecosystems.
What You’ll Bring
- Application security assessment experience. Direct experience conducting low-level code security assessments of complex software, identifying and mitigating application and system-level vulnerabilities. You read the code, not just the scanner output.
- Manual code review depth. Hands-on experience performing manual code reviews to find vulnerabilities that automated tools miss. You can explain why a bug is exploitable, not just that a tool flagged it.
- Static and dynamic analysis fluency. Experience using static and dynamic analysis tools as part of a deeper review process, including knowledge of where these tools fall short and how to extend them.
- Binary analysis and reverse engineering. Experience performing binary analysis and reverse engineering of compiled software. Comfortable with disassemblers, decompilers, and the surrounding tooling.
- Memory corruption vulnerabilities and mitigations. Demonstrated experience identifying memory corruption vulnerabilities and reasoning about modern mitigations. You understand the exploit primitives, not just the CWE category.
- System internals and security boundaries. Deep experience reasoning about system internals, IPC, access control implementations, and platform security boundaries in complex software.
- Architecture review and threat modeling. Experience performing architecture reviews and threat modeling of software systems and cloud environments, identifying weaknesses in data flows, authentication, and API design and proposing realistic remediation.
- Security tool development. Experience designing and building custom security tools for automated vulnerability detection. You bridge vulnerability research and application security by shipping tools, not just consuming vendor outputs.
- Programming proficiency across multiple languages. Hands-on experience programming in two or more of Rust, Golang, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, or C++, used for both security analysis and tool development.
- Communicating findings to technical stakeholders. Experience translating complex security findings into clear, actionable recommendations for engineering and security teams.
Nice to Have
- Experience with Android, iOS, or macOS system internals
- Experience contributing to open source security tools, libraries, or research
- Experience publishing original vulnerability research, CVEs, or technical writeups
- Experience speaking at security conferences (DEF CON, Black Hat, BSides, OffensiveCon, RECon, etc.)
- Experience identifying security misconfigurations in cloud environments (AWS, GCP, Azure)
- Experience collaborating on government-funded security research (DARPA, IARPA, ONR, etc.)
Compensation & Benefits
The base salary for this full-time position ranges from $100,000 to $200,000 excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range.
Benefits for full-time employees:
- Competitive salary complemented by performance-based bonuses
- Fully company-paid insurance packages, including health, dental, vision, disability, and life
- A solid 401(k) plan
Security Engineer II
Security Engineer II responsible for monitoring security alerts, responding to incidents, administering enterprise security tools, and supporting cloud and identity security initiatives. Requires 3+ years in cybersecurity or related fields with strong scripting and troubleshooting skills.
Security Engineer II
Security Engineer II responsible for monitoring and responding to security alerts, administering enterprise security tools, supporting vulnerability and IAM programs, and securing cloud environments. Requires 3+ years in cybersecurity or related fields and scripting experience.
Information Security System Officer
Enforce and maintain information security policies for CUI systems, ensuring NIST SP 800-171 compliance and CMMC 2.0 accreditation. Coordinate with ISSM, admins, and leadership on risk management, incident response, and continuous monitoring.
Security Engineer 1, Application Security
Security Engineer contributing to application security assessments, vulnerability discovery, and custom tooling development. Owns components of client engagements and drives findings from discovery through delivery.
Sr. Security Engineer, Incident Response
Technical lead for incident response across multi-cloud infrastructure. Owns triage, containment, automation, and detection tuning using CrowdStrike, Tines, and Cyberhaven DLP. Requires 5+ years in IR/SOC roles.