CareerPlanSign in

Security Engineer, Application Security

USA💼 Full-time🗓 2026-09-06 → 2026-09-25

Core

Embed security review workflows and PR-level analysis into the software development lifecycle, build and tune SAST/DAST pipelines, and manage vulnerability remediation for production applications.

Role type

Senior IC application security engineer

Builds

Secure coding standards, threat models for new features (including AI data pipelines and payment flows), and automated security pipelines integrated into CI/CD.

Domain

Web application security, software development lifecycle, AI/ML application security

Deliverable

production ML models | product features

Required skills

Web application security (OWASP Top 10, attack chains, business logic flaws), SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp), Python or TypeScript or Go, threat modeling, vulnerability management pipelines

Preferred skills

Bug bounty operations (HackerOne, Bugcrowd), penetration testing, supply chain security, custom security tooling, open source security contributions, published vulnerability research

Technologies

Semgrep, CodeQL, Snyk, Burp, Python, TypeScript, Go

Responsibilities

Embed security review workflows and PR-level analysis into the software development lifecycle; Build and tune SAST/DAST pipelines integrated into CI/CD; Create vulnerability management processes based on exploitability and drive findings through verified remediation; Develop secure coding standards and guardrails for more than 50 engineers; Create threat models for new features and architecture changes, including AI data pipelines, payment flows, and multi-tenant boundaries; Operate the bug bounty program by triaging HackerOne reports, validating findings, and driving fixes to closure

Seniority

Senior, hands-on IC

Sourced via codingjobboard · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.