Senior II Security Engineer - Application
Core
Own application and product security, partnering with engineering to embed security into the full SDLC and drive secure system design.
Role type
Senior IC application security engineer
Builds
Secure SDLC practices, security tooling (SAST/SCA/DAST), threat models, and engineering guardrails
Domain
EdTech, web applications, cloud-native environments
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
application security, web/API security risks, SDLC security integration, security tooling selection and scaling, threat modeling, secure coding review, stakeholder influence, automation, vulnerability management
Preferred skills
identity and authorization patterns (OAuth/OIDC, SSO, RBAC/ABAC), cloud-native security (AWS, Kubernetes), internal security library development, bug bounty/pentesting workflows, mobile security
Technologies
Python, Django, Snyk, CI/CD pipelines, AWS, Kubernetes
Responsibilities
Lead threat modeling for new features, mature code and application security tooling, improve vulnerability management, create secure development guardrails, deliver security training to engineers, partner with GRC on security controls
Seniority
Senior, hands-on IC