Application Security Engineer
Core
Full-stack security (edge + cloud + app) for a global PaaS platform, focusing on defensive and offensive measures to protect customers and platform availability.
Role type
Senior Application Security Engineer (IC)
Builds
Global PaaS platform for nonprofit fundraising and donor management
Domain
Cloud Security / Application Security / Nonprofit Technology
Deliverable
production ML models | product features | infrastructure
Required skills
Cloudflare stack management, WAF rule creation, Cloudflare Workers development, vulnerability triage, internal penetration testing, business logic analysis, dependency vulnerability assessment
Preferred skills
Experience with 3rd-party researcher programs, virtual patching at the edge, proactive risk identification
Technologies
Cloudflare, Cloudflare Workers, WAF, Intigriti, Dependabot
Responsibilities
Monitor traffic patterns to identify and mitigate threats like DDoS and credential stuffing; Write custom WAF expressions and Workers to intercept L7 attacks; Lead 3rd-party researcher program to triage and validate vulnerability reports; Design and execute targeted internal penetration tests focusing on real-world attack paths; Monitor and respond to vulnerabilities in application dependencies and frameworks
Seniority
Senior, high-autonomy IC
