Application Security Engineer
Core
Protecting the security and privacy of the SmartRent platform through risk management, compliance, and secure software development lifecycle practices.
Role type
Application Security Engineer
Builds
Secure software development lifecycle (SDLC) practices, secure coding standards, and application security workflows for the rental housing platform.
Domain
PropTech / Rental Housing / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security strategy, secure coding standards, vulnerability triage and remediation, SAST/DAST/SCA tools, cloud security controls, threat modeling, encryption and key management, OWASP Top 10 knowledge, modern authentication (JWT/OAuth), bug bounty program management.
Preferred skills
CSSLP/GIAC GWAPT/CEH certifications, CloudFlare/AWS security services integration, SDLC security integration, application security architecture reviews.
Technologies
AWS, WAF, GHAS, Burp Suite, Fortra, SAST, DAST, SCA, JWT, OAuth, Elixir, JavaScript, Ruby, Python, LLMs.
Responsibilities
Develop and execute application security strategy; maintain secure coding standards and documentation; deliver security training to development teams; review source code for vulnerabilities and AI-generated code risks; triage and support remediation of vulnerabilities; manage security workflows and ticket tracking; maintain responsible disclosure programs; partner on encryption and key management; perform threat modeling and attack path assessment; lead security incident investigation and mitigation; provide guidance on cloud infrastructure and IoT security; conduct risk assessments; research emerging risks; perform adversarial testing of applications and AI models; secure LLM integrations.
Seniority
Mid-Senior, hands-on IC