Senior Product Security Engineer, Application Security (Remote)
Core
Secure CrowdStrike's AI-native platform and customer-facing applications against advanced threats by identifying design flaws, performing secure code reviews, and collaborating with engineering teams to fix defects.
Role type
Senior IC application security engineer (web & API)
Builds
Secure code, hardened application architecture, and automated security tooling
Domain
Cybersecurity, Application Security, Cloud-Native
Deliverable
production ML models | product features
Required skills
Threat modeling (STRIDE), manual secure code review (Go, Python, JavaScript), browser security (Chrome, Firefox, Electron), API endpoint security testing, cloud-native security (AWS, Azure, GCP), SAST/DAST/CSPM tooling, application penetration testing, automation development
Preferred skills
Large-scale system experience, Docker/Kubernetes, WebAssembly, Kotlin, Scala, open source contributions, mentoring
Technologies
Go, Python, JavaScript, TypeScript, React, Node.js, Electron, AWS, Azure, GCP, Docker, Kubernetes, WASM
Responsibilities
Create and maintain threat models to drive security architecture review; Review application source code for security defects; Attack applications throughout the Secure Development LifeCycle; Build integrated tools and automation for security tasks; Drive response efforts for the bug bounty program; Collaborate with developers to implement proven security solutions
Seniority
Senior, hands-on IC
