CareerPlanSign in

Staff/Lead Application Security Engineer

San Francisco, CA💼 Full-time🗓 2026-08-18 → 2026-09-26

Core

Establishing the first dedicated application security program and strategy for Beacon's own engineering and portfolio companies' products.

Role type

Staff/Lead Application Security Engineer (Program Builder)

Builds

End-to-end application security program, security tooling, automation, and secure coding standards.

Domain

Application Security, Cloud Security, AI Security, Identity & Access Management

Deliverable

production ML models | product features | infrastructure

Required skills

Web and API security, Identity and Access Management (IAM), Applied Cryptography, Secure Code Review, Threat Modeling, Vulnerability Management, CI/CD Integration, AI Security Assessment

Preferred skills

Experience building security programs from scratch, Cloud-native security, Container security, Penetration testing management

Technologies

SAST, DAST, SCA, Secrets scanning tools, CI/CD pipelines

Responsibilities

Lead threat modeling and security architecture reviews, Perform secure code review for authorization and business logic flaws, Manage external penetration testing and remediation, Assess AI features and agent architectures, Own vulnerability management program and remediation SLAs, Build automation for security tooling and routine fixes, Write secure coding standards and training, Serve as security expert during incidents, Partner with GRC for compliance evidence

Seniority

Staff/Lead, hands-on IC with program ownership

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.