Application Security Engineer
Core
Build security into a defense-focused SaaS platform by embedding automated scanning and threat modeling into the SDLC to protect customer data and ensure compliance.
Role type
Senior Application Security Engineer (DevSecOps)
Builds
Secure SaaS platform features and CI/CD pipelines for defense AI systems
Domain
Defense technology / AI / Cloud Security
Deliverable
production ML models | product features | infrastructure
Required skills
Application security, DevSecOps, CI/CD automation, threat modeling, vulnerability management, container security, Python, TypeScript/JavaScript, GitHub Actions
Preferred skills
LLM security, NIST Risk Management Framework, U.S. defense contractor experience
Technologies
GitHub Actions, Python, TypeScript, JavaScript
Responsibilities
Implement and deploy SAST, SCA, secrets scanning, DAST, and container/IaC checks in CI/CD; Embed with development teams to run threat models and review critical PRs; Drive shift-left vulnerability detection; Coordinate with DevOps on cross-layer security issues; Support incident response and feed lessons back into code and process.