Skip to content

Staff AppSec Engineer

210k – 230kWashington, DCSecurity EngineeringHybrid6+ YOE
Summary

Staff AppSec Engineer owning end-to-end vulnerability identification and remediation. Partner with engineering teams on secure development practices, threat modeling, and AWS security architecture while leveraging AI tools.

About the role

Responsibilities

  • Own identification and remediation of application vulnerabilities end-to-end
  • Leverage AI tools to design and deliver scalable security solutions
  • Execute automated security testing (SAST, SCA) and work directly with engineers to resolve findings
  • Develop threat models and collaborate with product and engineering teams to surface, document, and prioritize risk
  • Advise leadership on security architecture decisions and application security best practices
  • Build developer security literacy through training, enablement, and vulnerability management guidance
  • Participate in penetration testing efforts and support bug bounty program operations
  • Contribute to the administration of AWS Control Tower and IAM provisioning workflows
  • Stay current with the broader security community and bring emerging trends back to the team

Requirements

  • 6+ years in application security or product security, including hands-on experience reviewing Python code
  • Track record of building and delivering solutions in vulnerability management programs
  • Deep expertise in AWS security architecture, including Lambda and AWS Control Tower
  • Demonstrated experience adopting and integrating AI tools into security or engineering workflows
  • Strong communication and collaboration skills

Nice-to-Haves

  • Bachelor's degree in Computer Science, Engineering, or a related field preferred

Tools & Technologies

  • GitHub Advanced Security, GitHub Actions, GitHub Copilot
  • Python
  • Terraform
  • AWS (Lambda, DynamoDB, S3, SNS, SQS, IAM, VPCs)
  • ChatGPT
  • Snowflake
  • SQL

Compensation & Benefits

  • US base salary range: $210,000 - $230,000 + equity + benefits
  • Medical, dental, and vision coverage starting on Day 1
  • Equity (ISOs)
  • 401(k) program
  • Family planning programs + paid parental leave
  • Physical fitness and wellness memberships
  • Emotional and mental health support programs
  • Unlimited PTO + 10 paid federal holidays + annual week-long Winter Break
  • Flexible work environment
  • Lunch reimbursement for in-office employees
  • Employee Resource Groups
  • Learning and Development stipend
Skills
PythonAWSAWS LambdaAWS Control TowerTerraformGitHub Advanced SecurityGitHub ActionsSASTSCAIAMThreat ModelingPenetration TestingVulnerability ManagementAI Tools
Similar roles at this salary range
All Security Engineering jobs →
Vercel

Security Software Engineer, IAM

Own IAM strategy and architecture across corporate and production environments. Migrate Okta to Terraform, enforce least-privilege access, and drive automation for provisioning and device management.

208k – 312kUnited StatesSecurity EngineeringRemote7+ YOESSOMFA
Everlaw

Senior Software Security Engineer

Lead security engineering efforts at Everlaw, guiding a team to build secure development practices and protect customer data on AWS. Requires 4+ years in security and Python scripting skills.

215k – 272kOakland, CASecurity EngineeringOn-site4+ YOEAWSIAM
Novig

Senior Security Engineer

Senior Security Engineer building proactive, automated security systems including SOAR/SIEM workflows, AI agents, vulnerability management, and cloud hardening for a fast-growing sports prediction market platform.

200k – 250kNew York, NYSecurity EngineeringOn-site5+ YOECDKIAM
Instacart

Senior Security Engineer, Cloud, AI, Product Security

Senior Security Engineer responsible for identifying infrastructure and product risks, defining remediation roadmaps, and building scalable secure engineering systems. Requires 5+ years in security engineering and strong IaC and code review experience.

192k – 242kUnited StatesSecurity EngineeringRemote5+ YOEGoOPA
Coinbase

Senior Software Engineer

Senior Software Engineer on the Core Cryptography team building and operating Tier-0 cryptographic infrastructure including MPC systems that secure 99% of customer assets. Requires 5+ years building highly available distributed systems and experience with applied cryptography, KMS/HSMs, and systems languages (Golang-heavy).

186k – 219kUnited StatesSecurity EngineeringRemote5+ YOEC++Java