Application Security Engineer
Core
Own the end-to-end security posture of a product platform spanning mobile apps, REST APIs, microservices, and cloud infrastructure, integrating early in the engineering lifecycle.
Role type
Application Security Engineer (IC)
Builds
Secure product features, AI-native models, and cloud infrastructure
Domain
Cybersecurity, Cloud-Native, AI/LLM Security
Deliverable
production ML models | product features | infrastructure
Required skills
Threat modeling, manual penetration testing, secure coding program design, vulnerability management, SAST/DAST/IAST/SCA tool integration, cloud-native security (Kubernetes, IAM, service mesh), AI/LLM security assessment, scripting/automation
Preferred skills
Cloudflare WAF experience, red-team testing, building AI-based security tools
Technologies
Kubernetes, Istio, Keycloak, OIDC, JWT, AWS, DigitalOcean, GCP, Firebase, Python, Bash
Responsibilities
Perform manual penetration testing on web apps, APIs, and Android apps; conduct security reviews for AI-native products; onboard applications into SSDLC; own security incident response; tune SAST/DAST tools in CI/CD; review and harden cloud infrastructure; communicate risks to stakeholders; conduct security training
Seniority
Mid-level, hands-on IC
