Application Security Engineer
Core
Improving the security posture of applications, services, and the development ecosystem by integrating security into the software development lifecycle.
Role type
Application Security Engineer
Builds
Secure-by-default patterns, security automation, guardrails, and reusable components for enterprise data intelligence platforms.
Domain
Enterprise data intelligence, distributed data environments, AI and analytics infrastructure.
Deliverable
production ML models | product features | infrastructure
Required skills
Application vulnerability mitigation (OWASP Top 10, CWE), CI/CD pipeline integration, secure code reviews, threat modeling, cloud security (AWS/Azure/GCP), programming (Python/Go/Java/JavaScript/Typescript), SAST/DAST/SCA tools, API security, secrets management.
Preferred skills
Secure coding principles, application hardening practices, incident response, secure deployment workflows.
Technologies
Trino, Apache Iceberg, OWASP ZAP, Burp Suite, Git, Python, Go, Java, JavaScript/Typescript, Ruby, AWS, Azure, GCP.
Responsibilities
Integrate automated security checks into CI/CD pipelines; conduct secure code reviews and threat modeling; develop security automation and guardrails; assist in incident response and vulnerability triage; define secure coding standards; improve application-level logging and telemetry.
Seniority
Mid-level, hands-on IC