Application Security Engineer
Core
Ensuring the technology stack is free of software vulnerabilities (CVEs) and securing base OS images, OSS dependencies, and CI/CD pipelines.
Role type
Application Security Engineer
Builds
Secure, vulnerability-free software deployments and CI/CD pipelines
Domain
Enterprise SaaS / Work AI / Cloud Security
Deliverable
production ML models | product features | infrastructure
Required skills
vulnerability management, supply chain risk mitigation, SAST/DAST integration, secure coding practices, penetration testing, automated security validation, security-first culture adoption
Preferred skills
Google Assured Open Source Software adoption, custom security solution development, cross-functional security leadership
Technologies
Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP, npm, pip, Maven, Go modules, AWS, GCP, Azure, Kubernetes, microservices
Responsibilities
Implement and improve the vulnerability management lifecycle; Continuously scan, monitor, and patch OSS dependencies; Integrate SAST, DAST, and dependency scanning tools into CI/CD; Define and maintain best practices for secure coding; Ensure secure posture in SDLC via design reviews and penetration testing; Develop automated security validation tests; Lead adoption of security solutions; Provide security guidance and mentorship to engineering teams
Seniority
Mid-Senior, hands-on IC