Senior Application Security Engineer
Core
Validates application services and underlying dependencies for high security standards, implementing secure development practices and mitigating risks across the software lifecycle.
Role type
Senior Application Security Engineer (IC)
Builds
Secure application services, AI/LLM stacks, and secure software supply chains
Domain
Real estate analytics and data solutions
Deliverable
production ML models | product features
Required skills
Application security testing (SAST, DAST, SCA), threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, cloud security (AWS, private cloud), scripting (Java, Python, C++, Ruby, JavaScript, PowerShell, PHP), secure coding practices
Preferred skills
AI security initiatives, prompt injection risk mitigation, third-party model auditing, security frameworks (ISO 27001, NIST, GDPR, CIS, SOC 2)
Technologies
SAST tools, DAST tools, SCA tools, AWS, private cloud environments
Responsibilities
Plan and carry out application security testing in all phases of the software development life cycle; Assess discovered vulnerabilities and recommend risk-mitigating solutions; Lead AI security initiatives including threat modeling production LLM stacks; Collaborate with architects and development teams to drive secure design practices; Train developers and junior application security engineers on weaknesses to avoid; Regularly monitor the security community for public-facing security issues
Seniority
Senior, hands-on IC
