Application Security Engineer
Core
Application Security Engineer helping product teams build and ship securely by default through secure design reviews, threat modeling, code review, and CI/CD integration.
Role type
Senior hands-on IC Application Security Engineer
Builds
Secure-by-default software products and services for enterprise teams
Domain
SaaS work management platform, cloud-native, web and API security
Deliverable
production ML models | product features | infrastructure
Required skills
web and API security, authentication and session management, secrets handling, secure coding fundamentals, SAST/SCA/DAST tooling, threat modeling, CI/CD integration, OAuth/OIDC, cloud/container security concepts
Preferred skills
AppSec automation, secure coding guidance, privacy-sensitive systems, cloud-native services, multi-service architectures, AI/ML product security
Technologies
Java, TypeScript, PHP, SAST, SCA, DAST, bug bounty platforms, CI/CD pipelines, structured AI workflows
Responsibilities
Own recurring Application Security activities for multiple product teams including secure design reviews, threat modeling, code review, testing validation, and remediation guidance; Assess vulnerabilities and findings from scanners and testing to distinguish meaningful risk; Validate security fixes and recommend compensating controls; Improve AppSec workflows by tuning checks and integrating security into developer workflows and CI/CD pipelines; Help engineers understand security findings by providing clear prioritization and actionable remediation guidance; Contribute to secure-by-default development practices by reinforcing standards and reference patterns; Use structured AI workflows to support complex AppSec analysis while maintaining guardrails around prompt hygiene and human oversight
Seniority
Senior, hands-on IC