Application Security Engineer
Core
Define, build, and operate application vulnerability identification, triage, and remediation capabilities across consumer products, internal tools, and GraphQL APIs; build offensive security capabilities and establish secure-by-default standards for AI-enabled applications.
Role type
Senior IC Application Security Engineer (DevSecOps & Offensive Security)
Builds
Automated vulnerability triage workflows, AI agents for exploit validation, secure CI/CD guardrails, and hardened authentication/authorization for APIs and Kubernetes workloads.
Domain
Application Security, Cloud Security, AI/ML Security, Offensive Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security engineering, Software development (Python, Go, TypeScript, Ruby), Threat modeling, Cloud security (AWS, Kubernetes), CI/CD pipeline security, GraphQL security, Secrets management, Bug bounty program management, Red-team operations, AI agent development
Preferred skills
Penetration testing, Mobile application security, API security, MCP integrations, Offensive security certifications (OSCP, OSWE)
Technologies
GitHub Advanced Security, Semgrep, Kubernetes, AWS, GraphQL, Linear, Slack, MCP servers
Responsibilities
Operate AppSec tooling for static/dynamic testing and supply-chain risk detection; Lead threat modeling and security design reviews; Build AI agents for automated vulnerability triage and remediation; Partner with engineering to harden services and Kubernetes workloads; Conduct internal red-team exercises and adversarial analysis.
Seniority
Senior, hands-on IC

