Application Security Engineer
Core
Build and mature an application security program for a scaling multi-tenant SaaS platform, embedding security into the SDLC and enabling developers to own security in their code.
Role type
Senior IC Application Security Engineer
Builds
Secure features, APIs, and cloud-native components for a SaaS platform serving employees.
Domain
SaaS, Cloud Security, Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security fundamentals, Web and API security, OWASP Top 10, Secure coding, SAST/DAST/Dependency scanning, CI/CD integration, Threat modeling, Cryptography, Authentication/Authorization
Preferred skills
AI-assisted security tooling, Secure coding training/mentoring, Compliance frameworks (SOC 2, ISO 27001)
Technologies
GitHub Advanced Security, Snyk, Wiz, SAST, DAST, Container scanning, CI/CD pipelines
Responsibilities
Embed security checkpoints into planning, design, development, testing, and release processes; Partner with engineering leads to ensure new features ship with security built in; Facilitate threat modeling for new services, APIs, and integrations; Recommend secure patterns and architectures for multi-tenant SaaS and cloud-native components; Perform targeted secure code reviews for high-risk features; Configure and tune SAST, DAST, dependency, and container scanning; Integrate and optimize AI-assisted application security tools into developer workflows; Triage, prioritize, and track remediation of application and API vulnerabilities; Advise on secure use of authentication, authorization, cryptography, and data protection controls; Build and deliver pragmatic secure coding training; Create playbooks, checklists, and self-service guidance for developers; Champion a "secure by default" mindset; Assist with investigation and remediation for application-level security incidents; Help improve detection, logging, and alerting for application and API misuse.
Seniority
Senior, hands-on IC