Application Security Engineer [Remote-US]
Core
Build secure-by-default products and services for an AI-native insurance technology platform by embedding security throughout the software development lifecycle.
Role type
Application Security Engineer
Builds
Secure AI-native insurance technology platform
Domain
Insurance + Application Security
Deliverable
production ML models
Required skills
Threat modeling, secure code reviews, vulnerability analysis, automated security guardrails, secure coding practices, compliance and risk management, security standards development, cloud platform knowledge, programming language proficiency
Preferred skills
Security certifications (CSSLP, GWEB, OSWE), regulated industry experience, cloud security architecture, mobile app security, penetration testing, AI/LLM security, security automation scripting
Technologies
OWASP Top 10, ASVS, MASVS, STRIDE, PASTA
Responsibilities
Partner with Product and Engineering to integrate security into design and development; Lead threat modeling exercises; Conduct secure code reviews and vulnerability analysis; Develop automated security guardrails; Investigate and drive remediation of security findings; Promote secure coding practices through training; Collaborate on compliance and risk management; Create and maintain security standards.
Seniority
Mid-Senior (4–6+ years total, 2+ in app security)
