Job Description
About the Role
Software is being written faster than ever by engineers and, increasingly, by AI assistants. We're hiring an Application Security Engineer who can keep pace: someone who lives in the pipeline, partners closely with engineering, and brings hard-earned judgment to a fast-moving SDLC.
You will own and evolve our Secure SDLC and DevSecOps practice, harden the software supply chain, and build the guardrails that let our teams adopt AI-assisted coding tools safely. Your work will directly support our ISO 27001:2022 and SOC 2 Type II programs.
What You'll Do
- Embed security into the SDLC: threat modeling (STRIDE / PASTA), secure design reviews, secure code review, and security acceptance criteria for new features.
- Run the AppSec toolchain: operate and tune SAST, DAST, SCA, IaC, container, and secrets-scanning tools (e.g., Snyk, Semgrep, Checkmarx, GitHub Advanced Security, Trivy, Checkov, GitGuardian).
- Govern AI-assisted development: define policies for Copilot / Cursor / agentic-coding usage, set review standards for AI-generated code, and address risks like prompt injection, license contamination, and insecure suggestions.
- Own software supply chain security: SBOM generation (CycloneDX / SPDX), artifact signing (Sigstore / cosign), build provenance aligned with SLSA, and dependency risk management.
- Drive vulnerability management: triage findings using CVSS, EPSS, and reachability context; partner with engineering to meet remediation SLAs and reduce backlog over time.
- Perform targeted assessments: manual security testing and architecture reviews on high-risk web, mobile, API, and cloud-native workloads (AWS / Azure / GCP).
- Support audits and compliance: map controls to OWASP ASVS 5.0, OWASP API Top 10, OWASP LLM Top 10, CWE Top 25, and produce audit evidence for ISO 27001 and SOC 2.
- Build a security culture: run secure-coding training, an AppSec Champions program, and brown-bag sessions on emerging threats and Vibe Coding best practices.
- Respond when it counts: participate in incident response when application-layer issues are involved, and lead post-incident security retrospectives.
Must-Have Skills & Experience
- 3+ years hands-on in Application Security, Product Security, or DevSecOps in a SaaS / product environment.
- Demonstrated experience with at least two of: SAST, DAST, SCA, IaC scanning, container scanning, secrets detection — including tuning rules and reducing false positives.
- Strong working knowledge of OWASP Top 10, ASVS, API Security Top 10, OWASP LLM Top 10, and the CWE Top 25.
- Comfortable reading and reviewing code in at least two of: Java, Python, Go, JavaScript / TypeScript, C#, Kotlin.
- CI/CD security experience with GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
- Working knowledge of one or more major cloud platforms (AWS, Azure, GCP) and the basics of Kubernetes / container security.
- Practical exposure to ISO 27001:2022 and SOC 2 evidence workflows; comfort working with auditors.
- Excellent written and verbal communication — you can explain a finding to both an engineer and an exec.
Nice to Have
- Hands-on securing LLM / GenAI features — RAG pipelines, agents, fine-tuning workflows — and red-teaming for prompt injection, model abuse, or data exfiltration.
- Experience with Application Security Posture Management (ASPM) platforms such as Apiiro, ArmorCode, or Cycode.
- Familiarity with runtime security and eBPF-based tooling, or with Wiz / Orca / Lacework for cloud-native risk.
- Bug bounty program ownership, responsible disclosure handling, or published CVEs.
- Contributions to open-source security tools, OWASP projects, or security research.
Preferred Certifications
Any of the following are a strong plus: CSSLP, OSCP, OSWE, GWAPT, Burp Suite Certified Practitioner, AWS / Azure / GCP Security Specialty, GitHub Advanced Security, or IAPP AIGP.
Success Metrics (First 12 Months)
- 40% year-over-year reduction in Critical / High vulnerabilities reaching production.
- Mean Time to Remediate (MTTR) for Critical findings 7 days; High findings 30 days.
- 95% of active repositories integrated with SAST and SCA; 90% with secrets scanning.
- 100% audit-evidence readiness for ISO 27001 and SOC 2 cycles, with zero major findings tied to AppSec.
- 90% engineering completion of annual secure-coding training; AppSec Champions in every product team.
What You'll Get
- High-impact work at the intersection of Application Security and AI engineering.
- Sponsored certifications, conference budget (e.g., DEF CON, Black Hat, OWASP Global AppSec), and a structured learning plan.
- Modern tooling stack and real autonomy to evaluate, pilot, and adopt new technology.
- Hybrid work model with flexibility for deep-focus days and collaborative days.
- Competitive compensation, comprehensive health benefits, parental leave, and wellness support.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.