Application Security Engineer
Core
Define, build, and operate application vulnerability identification, triage, and remediation capabilities across consumer products, internal tools, and GraphQL APIs; build offensive security capabilities and establish secure-by-default standards for AI-enabled applications.
Role type
Senior IC Application Security Engineer (Offensive Security & AI Security)
Builds
Automated vulnerability triage workflows, AI agents, security guardrails, and secure AI/agent architectures
Domain
Application Security, API Security, Cloud Security, AI/ML Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security engineering, offensive security, threat modeling, security design reviews, API security (GraphQL/REST/gRPC), cloud/container security (AWS/Kubernetes), CI/CD pipeline security, agentic system development, programming in Python/Go/TypeScript/Ruby
Preferred skills
Penetration testing, red team operations, bug bounty program management, AI/ML pipeline security, MCP-style integrations
Technologies
GitHub Advanced Security, Semgrep, Kubernetes, AWS, MCP servers
Responsibilities
Build and operate vulnerability identification and remediation capabilities; own and mature the bug bounty program; lead threat modeling and security design reviews; build AI agents for automated vulnerability triage; partner with engineering to improve authentication, authorization, and workload security; conduct internal security testing and red team exercises.
Seniority
Senior, hands-on IC
