Skip to content

Staff Application Security Engineer

228k – 290kSan Francisco, CAHybrid10+ YOE
Summary

Lead application security initiatives as a technical leader on a new security team. Drive threat modeling, secure SDLC, code reviews, vulnerability management, and AI security for a healthcare AI platform.

About the role

Secure Development & Architecture Leadership

  • Lead Threat Modeling and Design Reviews: Conduct advanced threat modeling and security architecture reviews for complex systems, new products, and platform initiatives.
  • Define Security Strategy: Define and implement the technical roadmap for the Application Security program, focusing on scalable assurance and proactive security measures.
  • Mentor and Enable: Act as a subject matter expert and trusted advisor to product and engineering teams, providing mentorship on security features, product defense, secure coding practices, application architecture, and vulnerability remediation strategies.
  • Conduct Training & Awareness: Develop training materials for engineers to build a foundation of security best practices.

Vulnerability Management & Incident Response

  • Code and Security Reviews: Perform and lead in-depth secure code reviews (both manual and tool-assisted) to identify complex security vulnerabilities and flaws, including logic and authorization vulnerabilities.
  • Internal Penetration Testing: Lead internal penetration testing engagements for net new products and historical systems.
  • Vulnerability Program Oversight: Design and enhance the end-to-end vulnerability management program for products and applications, ensuring timely identification, prioritization, and remediation of critical security issues.
  • Security Incident Response: Serve as an expert on products and applications for the security incident response team, assisting in investigating and resolving security events and incidents.

What You’ll Bring

  • 10+ years of direct experience in an Application Security role, with a demonstrated history of designing and implementing security improvements at scale.
  • Deep proficiency in one or more major programming languages (Python and NextJS a big plus) and a solid background in software development principles.
  • Extensive experience securing applications deployed in Cloud environments (GCP a big plus) and knowledge of containerization technologies (Kubernetes).
  • Expert-level knowledge of web application security techniques and principles, APIs, IAM (including identity, authentication/authorization, RBAC, ABAC), applied cryptography.
  • Deep understanding of the security of AI and ML models, agents, and associated systems.

Bonus Points If…

  • Proven experience contributing to or leveraging open-source security tools, publishing security research, managing bug bounty programs, and active engagement in the security industry.
  • Demonstrated ability to drive large, cross-functional technical projects that impact security posture across the entire organization.
  • Experience defining and utilizing security metrics to measure and report on the effectiveness of the AppSec program to both technical and executive audiences.
Skills
PythonNext.jsGCPKubernetesThreat ModelingSecure Code ReviewPenetration TestingIAMApplied CryptographyAI/ML Security
Similar roles at this salary range
All Security Engineering jobs →
Upstart

Principal Security Engineer, Data Security

Principal-level security engineer defining infrastructure security strategy and leading cross-functional efforts to secure cloud, Kubernetes, and developer platforms at scale.

191k – 264kUnited StatesSecurity EngineeringRemote8+ YOEGoAWS
Brex

Senior Application Security Engineer

Senior Application Security Engineer focused on finding vulnerabilities, performing penetration testing, and building security tooling across Brex's platform. Requires 5+ years in application security with strong Python and AI workflow knowledge.

192k – 240kUnited StatesSecurity EngineeringRemote5+ YOEAWSgRPC
Rula

Staff Software Engineer - Trust & Safety

Staff-level engineer to found and lead a new Trust & Safety engineering team, architecting systems to detect fraud, billing anomalies, and credential abuse for a mental healthcare platform.

207k – 243kLos Angeles, CASecurity EngineeringRemote8+ YOESQLAWS
Apollo

Senior Application Security Engineer

Senior individual contributor responsible for strengthening Apollo's secure software development lifecycle, performing application security reviews, threat modeling, vulnerability management, and AI security for product, platform, and AI-powered features.

190k – 273kUnited StatesSecurity EngineeringRemote5+ YOEGCPRuby
Betterment

Sr. Engineering Manager, Application Security

Senior Engineering Manager leading Application Security squad to build secure software by default through threat modeling, design reviews, vulnerability management, and developer tooling. Requires hands-on team leadership and expertise across the AppSec stack.

210k – 250kNew York, NYSecurity EngineeringHybrid7+ YOEAWSCI/CD