Application Security Engineer
Core
Drive security across the SDLC at scale by building automated security controls, vulnerability management frameworks, and internal security tools for cloud-native services and SaaS products.
Role type
Senior IC application security engineer (DevSecOps)
Builds
Scalable vulnerability management frameworks, internal security tools, and AI agents for SSDLC automation
Domain
Software security, DevSecOps, cloud-native services, SaaS
Deliverable
production ML models | product features | infrastructure
Required skills
Application security, vulnerability management, CI/CD pipeline automation, secure coding principles, threat modeling, SAST/DAST/SCA integration, Python/Go/Java/JavaScript, cloud-native architectures, microservices, containers, Kubernetes
Preferred skills
Penetration testing, machine learning concepts for security (anomaly detection, predictive analytics)
Technologies
Python, Go, Java, JavaScript, Kubernetes, CI/CD tools, SAST/DAST/SCA tools
Responsibilities
Design and implement SSDLC practices and automated security controls across CI/CD pipelines; Build and operate scalable vulnerability management frameworks; Develop internal application security tools and automations; Integrate security into Agile and DevOps processes; Partner with development and DevOps teams to embed security early; Track, triage, and report vulnerabilities across product lines
Seniority
Senior, hands-on IC
