Application Security Engineer
Core
Own day-to-day application security vulnerability management, operate bug bounty programs, and build security automation to secure mobile and backend software.
Role type
Application Security Engineer II (hands-on IC)
Builds
Secure mobile and backend software platforms for millions of users
Domain
Health & Fitness / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security assessment (SAST, DAST, SCA, penetration testing), Vulnerability management and triage, Secure development practices (OWASP Top 10, MASVS), AI/agentic tooling usage, Security automation (Python, SOAR), Cloud microservices (Kubernetes, IaC), Identity and access management workflows
Preferred skills
Security scanning in CI/CD pipelines, Bug bounty program operation, Security process automation
Technologies
Python, SOAR, GitHub Actions, Kubernetes, Claude Code, LLM-powered workflows
Responsibilities
Triage findings from SAST, SCA, DAST, and mobile security tooling; Operate and grow bug bounty program; Build and maintain security automation; Partner with engineering teams on remediation; Perform security reviews of new features and integrations; Administer application security tooling across SDLC
Seniority
Mid-level, hands-on IC