Senior Application Security Engineer
Core
Technical leader on application security setting standards, defining secure-to-ship criteria, and driving remediation for a platform handling customer PII, passenger manifests, and payment flows.
Role type
Senior IC application security engineer
Builds
Security tooling, automation, and developer guardrails for a two-sided marketplace platform
Domain
Transportation and mobility / Application Security
Required skills
Java, TypeScript, threat modeling, secure system design, authentication, authorization, access control, injection prevention, SSRF, manual code review, AWS IAM, multi-account architecture, CI/CD security, vulnerability management
Preferred skills
SOC 2, PCI DSS, GDPR compliance knowledge
Technologies
AWS, Java, TypeScript, SAST, container scanning, secret detection
Responsibilities
Own security tooling and vulnerability management across SAST, dependency and container scanning, secret detection, and penetration testing; Lead security design reviews, threat modeling, and targeted manual code reviews for high-risk systems; Identify and prevent multi-tenant authorization vulnerabilities; Strengthen AWS security through IAM and account boundary design; Scale security across engineering by building secure defaults and establishing a security champions practice
Seniority
Senior, hands-on IC
