Application Security Engineer [Remote-US]
Core
Build secure-by-default products and services for an AI-native insurance technology platform by embedding security throughout the software development lifecycle.
Role type
Application Security Engineer
Builds
Secure AI-native insurance technology platform
Domain
Insurance technology, AI, Cloud security
Deliverable
production ML models | product features
Required skills
Application security, Threat modeling, Secure code review, Vulnerability analysis, Secure development lifecycle (SDLC) integration, Cloud platforms, Programming languages, OWASP Top 10, ASVS, MASVS, STRIDE, PASTA
Preferred skills
Security certifications (CSSLP, GWEB, OSWE), Regulated industry experience, Cloud security architecture, Mobile app security, Penetration testing, AI/LLM security, Automation scripting
Technologies
Cloud platforms, AI/LLM frameworks, Security testing tools
Responsibilities
Partner with Product and Engineering to integrate security into design and development, Lead threat modeling exercises, Conduct secure code reviews and vulnerability analysis, Develop automated security guardrails, Investigate and drive remediation of security findings, Promote secure coding practices through training, Collaborate on compliance and risk management, Create and maintain security standards
Seniority
Mid-Senior, hands-on IC
