Security Engineer, Application Security
Core
Embed security review workflows and PR-level analysis into the software development lifecycle, build and tune SAST/DAST pipelines, and manage vulnerability remediation for production applications.
Role type
Senior IC application security engineer
Builds
Secure coding standards, threat models for new features (including AI data pipelines and payment flows), and automated security pipelines integrated into CI/CD.
Domain
Web application security, software development lifecycle, AI/ML application security
Deliverable
production ML models | product features
Required skills
Web application security (OWASP Top 10, attack chains, business logic flaws), SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp), Python or TypeScript or Go, threat modeling, vulnerability management pipelines
Preferred skills
Bug bounty operations (HackerOne, Bugcrowd), penetration testing, supply chain security, custom security tooling, open source security contributions, published vulnerability research
Technologies
Semgrep, CodeQL, Snyk, Burp, Python, TypeScript, Go
Responsibilities
Embed security review workflows and PR-level analysis into the software development lifecycle; Build and tune SAST/DAST pipelines integrated into CI/CD; Create vulnerability management processes based on exploitability and drive findings through verified remediation; Develop secure coding standards and guardrails for more than 50 engineers; Create threat models for new features and architecture changes, including AI data pipelines, payment flows, and multi-tenant boundaries; Operate the bug bounty program by triaging HackerOne reports, validating findings, and driving fixes to closure
Seniority
Senior, hands-on IC
