Senior Application Security Engineer
Core
Strengthen application and platform security posture by embedding security throughout the software development lifecycle for AI-driven marketing platforms.
Role type
Senior Application Security Engineer
Builds
Secure design principles, automated controls, and security tooling for cloud-native systems
Domain
Marketing technology, AI/ML platforms, Cloud-native infrastructure
Deliverable
production ML models | product features | infrastructure
Required skills
Threat modeling, SAST/DAST, dependency scanning, API security, OAuth2/OIDC/JWT, cloud platforms (AWS/GCP/Azure), containerization (Docker/Kubernetes), security testing tools (Semgrep/SonarQube/Burp Suite/Zap/Trivy)
Preferred skills
AI/ML security concepts (data poisoning, adversarial testing), automation frameworks and scripting
Technologies
React, Node.js, Django, FastAPI, AWS, GCP, Azure, Docker, Kubernetes, Semgrep, SonarQube, Burp Suite, Zap, Trivy
Responsibilities
Conduct threat modeling and security reviews for distributed cloud-native systems; Perform security code reviews, static/dynamic analysis, and dependency scanning; Partner with developers to embed security testing into CI/CD pipelines; Stay current on evolving security risks including AI/ML-specific threats like prompt injection and model poisoning
Seniority
Senior, hands-on IC