we are looking for a AppSec Architect.
As an AppSec Engineer, you'll be the security partner for our R&D teams - reviewing code and architecture, closing the loop on vulnerabilities, and helping developers ship secure features faster. You'll also own our external vulnerability disclosure channels end-to-end, including leading our Bug Bounty program. This role is a great fit if you have a development background, enjoy digging into code, and want to use AI tools and agents to scale security impact across a large, fast-growing platform.
Responsibilities
Application Security & Secure SDLC
Partner with R&D: work directly with developers to identify, triage, and remediate application-level vulnerabilities.
Review code & architecture: assess security weaknesses and provide clear, actionable, developer-friendly remediation guidance both in the code and architectural levels
Own the scanning pipeline: run and tune SAST, DAST, and SCA tools across the codebase and CI/CD.
Shift security left: drive secure coding practices, threat modeling, and security requirements into the development process.
Review new features: support security reviews for new products, integrations, and third-party dependencies.
Requirements: 2-4 years of experience in Application Security, Security Engineering, or Software Development with a strong security focus.
Development experience is a clear advantage - a hands-on coding background in any modern language or stack.
Solid understanding of common web and application vulnerability classes (e.g., OWASP Top 10).
Experience with Application Security Testing tools (such as burp suite, CI/CD pipeline security rule configuration etc)
Experience with SAST/DAST/SCA tools and integrating security into CI/CD pipelines.
Hands-on, practical familiarity with AI tools and building AI agents for real workflows.
Basic coding and scripting skills (Python, Bash, JavaScript, or similar).
Strong communication skills and the ability to work closely with developers and cross-functional teams.
This position is open to all candidates.