Required Senior Application Security Engineer
As a Senior Application Security Engineer, youll plan, build, and support efforts to strengthen security across the organization. As part of our Security & Platform organization, youll work across the software development lifecycle and the underlying cloud and platform environment.
Youll own application security throughout the SDLC, including security requirements, threat modeling, secure design reviews, code reviews, application and API security testing, and production hardening. The role combines application security, cloud and platform security, and security automation. Youll partner closely with Security, Engineering, Platform, DevOps, and IT teams to build secure-by-default systems and reduce risk at scale.
Youll also define and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance. This is a hands-on engineering role for someone who can move comfortably between architecture and threat modeling, code and API reviews, cloud and identity guardrails, CI/CD security controls, vulnerability remediation, and automation.
Responsibilities
Define, track, and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
Own application security across the SDLC, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
Strengthen cloud and platform security by implementing scalable security controls, identity guardrails, and secure-by-default practices.
Partner closely with Security, Engineering, Platform, DevOps, and IT teams to reduce security risk and improve security practices across the organization.
Designing controls for multi-account or multi-cloud environments using Terraform, policy-as-code technologies such as OPA or Sentinel, or automated remediation workflows.
Experience running a Security Champions, bug bounty or responsible disclosure program, or delivering hands-on secure engineering training.
You'll translate technical risk into clear remediation guidance and influence engineering and leadership stakeholders through strong written and verbal communication.
Requirements: 6+ years of relevant experience across security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering, including substantial hands-on security ownership.
Deep expertise in either application/product security or cloud/platform security, with demonstrated hands-on capability across the other domain.
Strong programming and automation skills; proficiency in Python is required, with Go or Bash beneficial, together with practical CI/CD and infrastructure-as-code experience.
Experience embedding security into the SDLC through threat modeling, secure design and code review, application/API testing and CI/CD controls, supported by strong knowledge of OWASP risks and secure design principles.
Hands-on experience with Kubernetes admission controls, image and dependency scanning, supply-chain security and CIS benchmarks.
Familiarity with OWASP ASVS/SAMM, NIST SSDF/CSF, MITRE ATT&CK, SOC 2 or ISO 27001 control environments.
Experience securing AI-assisted development workflows, enterprise AI tools, agent-based integrations, or MCP-connected systems.
This position is open to all candidates.