Application Security Engineer
Core
Ensuring security and integrity of cloud-native applications and systems throughout the software development lifecycle, with a focus on code security, CI/CD pipelines, and emerging AI technologies.
Role type
Application Security Engineer
Builds
Secure cloud-native applications and CI/CD pipelines
Domain
Cloud-native security, AI/ML security
Deliverable
production ML models | product features | infrastructure
Required skills
Secure coding practices, application security frameworks, CI/CD pipeline security, static/dynamic code analysis, software supply chain security, AI/ML security (OWASP LLM Top 10), Python, Rust
Preferred skills
Cloud platform security (GCP, AWS, Azure), GitOps, infrastructure-as-code security, custom security tooling, open-source security contributions
Technologies
Burp Suite, OWASP ZAP, SBOM tools, Python, Rust, GCP, AWS, Azure
Responsibilities
Conduct code reviews and static analysis to identify vulnerabilities; Design and implement secure coding guidelines; Integrate security practices into CI/CD pipelines; Perform threat modeling and risk assessments; Manage vulnerability tracking and remediation; Support incident response activities; Evaluate and secure software supply chains; Address security concerns specific to AI and machine learning models
Seniority
Mid-level, hands-on IC