Senior AppSec Engineer
Core
Embed security into every stage of the SDLC for web, mobile, platform, and AI-driven engineering environments, focusing on threat modeling, architectural reviews, and proactive risk reduction.
Role type
Senior IC Application Security Engineer
Builds
Secure microservices, AI/LLM integrations, and next-generation services with built-in privacy and security.
Domain
Cybersecurity, Application Security, Cloud Security, AI/LLM Security
Deliverable
production ML models | product features | infrastructure
Required skills
OAuth 2.0, OIDC, SAML, JWT, code review (Go, TypeScript, Python, C#), REST/GraphQL security, CI/CD pipeline security, supply chain integrity, WAF/Bot Management, mobile security controls
Preferred skills
AI/LLM security (prompt injection, tool-call abuse), iOS/Android binary hardening, Cloudflare edge products
Technologies
AWS, Kubernetes, GitHub Actions, Cloudflare, MCP, Bedrock, OWASP, SAST/DAST/SCA tools
Responsibilities
Lead threat modeling and architectural security reviews for complex microservices and AI features; Evaluate and improve OAuth 2.0/OIDC implementations; Tune and integrate SAST/DAST/SCA tools into CI/CD workflows; Perform deep-dive code reviews and provide remediation guidance; Prioritize and remediate vulnerabilities using WAF and mobile security tooling signals.
Seniority
Senior, hands-on IC
