Senior Security Engineer, Application Security
Core
Senior Application Security Engineer responsible for integrating security into the SDLC, managing vulnerability remediation, and leading offensive security engagements for a global wholesale marketplace.
Role type
Senior IC Application Security Engineer
Builds
Scalable, reusable security frameworks and CI/CD guardrails for a global B2B marketplace platform
Domain
E-commerce / Wholesale / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SAST/DAST/SCA/secret scanning, threat modeling, secure design reviews, vulnerability management lifecycle, offensive security (penetration testing), cloud security (AWS/GCP), OOP programming (Kotlin/Java/Python/TypeScript), AI-assisted code generation security
Preferred skills
Experience driving cross-team vulnerability remediation, tuning security tooling to reduce false positives, explaining technical risk to product engineers, leading threat models for systems not personally built
Technologies
Kotlin, TypeScript, Python, SAST/DAST/SCA, AWS, OCI, Terraform, Kubernetes, Cursor, Claude
Responsibilities
Find and fix vulnerabilities in first-party code and third-party dependencies using automated tooling; Build shift-left tooling and CI/CD guardrails; Own offensive security engagements including penetration tests; Evaluate and harden security of AI-assisted code generation workflows; Own the bug bounty program and vulnerability management lifecycle; Lead threat modeling and secure design reviews for new products; Conduct security reviews and consultations with product teams
Seniority
Senior, hands-on IC
