Application Security Engineer
Core
Own the vulnerability management lifecycle across SAST, DAST, and SCA tooling, integrate security automation into CI/CD pipelines, and serve as a trusted advisor to a 300+ person engineering organization.
Role type
Application Security Engineer (IC)
Builds
Automated security tooling integrations within CI/CD pipelines
Domain
SaaS / Cloud-native Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability management lifecycle ownership, SAST/DAST/SCA tooling proficiency, CI/CD pipeline integration, container security (Docker/Kubernetes), API security patterns (REST/GraphQL), technical risk communication
Preferred skills
Security Champions program leadership, AWS security services (GuardDuty, Security Hub, IAM), threat modeling frameworks (STRIDE, PASTA)
Technologies
Snyk, Checkmarx, Semgrep, Wiz, GitHub Actions, Jenkins, GitLab CI, Docker, Kubernetes, AWS
Responsibilities
Triage, prioritize, and drive remediation of findings from SAST, DAST, and SCA tooling; Maintain and extend security tooling integrations within the CI/CD pipeline; Launch and run a Security Champions program; Act as the application-layer subject matter expert during security incidents; Partner with Product and Engineering leadership to introduce security touchpoints earlier in the SDLC
Seniority
Mid-level, hands-on IC