Application Security Engineer
Core
Lead vulnerability management and secure the software supply chain for an enterprise Work AI platform.
Role type
Senior Application Security Engineer (Vulnerability Management & Supply Chain)
Builds
Secure base OS images, patched OSS dependencies, and integrated security tooling within CI/CD pipelines.
Domain
Enterprise AI / Cloud-Native Security
Deliverable
production ML models | infrastructure
Required skills
Vulnerability management lifecycle, CVE analysis, OWASP Top 10, SAST/DAST integration, dependency scanning, cloud-native security (AWS/GCP), Kubernetes, microservices, secure coding practices
Preferred skills
Google Assured Open Source Software (OSS), supply chain risk mitigation, cross-functional security adoption leadership
Technologies
Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP, AWS, GCP, Kubernetes
Responsibilities
Own the vulnerability management lifecycle from discovery to remediation; Harden base OS images and secure open-source dependencies; Integrate automated security validation into CI/CD pipelines; Evaluate and adopt new security solutions; Define secure-coding practices and drive engineering adoption
Seniority
Senior, hands-on IC with leadership responsibilities