Senior Application Security Engineer
Core
Building secure-by-default patterns, tooling, and defaults for web, mobile, and API ecosystems while shaping AI security integration.
Role type
Senior IC application security engineer (tooling & automation)
Builds
AppSec tooling stack (SAST, SCA, secrets scanning, DAST), secure pipelines, and AI security guardrails
Domain
Retail technology, cloud-native security, AI/LLM security
Deliverable
production ML models | infrastructure
Required skills
threat modeling, security design review, manual code review, application/API vulnerability analysis, cloud-native/container/serverless security, AI/LLM security judgment, fluent coding in Java/Kotlin/C#/Python
Preferred skills
GitHub Advanced Security, JFrog Artifactory, offensive security, vulnerability disclosure, production software engineering
Technologies
AWS, GCP, Azure, Kubernetes, SAST, SCA, secrets scanning, DAST, LLMs, agents
Responsibilities
Build secure-by-default patterns and paved-road tooling; own the AppSec tooling stack and tune it for signal over noise; automate security work that doesn't need human judgment; partner with security teams, mentor engineers, and raise the application security bar
Seniority
Senior, hands-on IC