CareerPlanSign in

Application Security Engineer

USA💼 Full-time🗓 2026-09-07 → 2026-09-25

Core

Define, build, and operate application vulnerability identification, triage, and remediation capabilities across consumer products, internal tools, and GraphQL APIs; build offensive security capabilities and establish secure-by-default standards for AI-enabled applications.

Role type

Senior IC Application Security Engineer (DevSecOps & Offensive Security)

Builds

Automated vulnerability triage workflows, AI agents for exploit validation, secure CI/CD guardrails, and hardened authentication/authorization for APIs and Kubernetes workloads.

Domain

Application Security, Cloud Security, AI/ML Security, Offensive Security

Deliverable

production ML models | product features | infrastructure

Required skills

Application security engineering, Software development (Python, Go, TypeScript, Ruby), Threat modeling, Cloud security (AWS, Kubernetes), CI/CD pipeline security, GraphQL security, Secrets management, Bug bounty program management, Red-team operations, AI agent development

Preferred skills

Penetration testing, Mobile application security, API security, MCP integrations, Offensive security certifications (OSCP, OSWE)

Technologies

GitHub Advanced Security, Semgrep, Kubernetes, AWS, GraphQL, Linear, Slack, MCP servers

Responsibilities

Operate AppSec tooling for static/dynamic testing and supply-chain risk detection; Lead threat modeling and security design reviews; Build AI agents for automated vulnerability triage and remediation; Partner with engineering to harden services and Kubernetes workloads; Conduct internal red-team exercises and adversarial analysis.

Seniority

Senior, hands-on IC

Sourced via codingjobboard · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.