Product Security Engineer, Application Security (Remote)
Core
Secure CrowdStrike's AI-native platform and web applications by identifying design flaws, reviewing code, and collaborating with engineers to ship secure software.
Role type
Senior IC application security engineer (cloud-native)
Builds
Secure code for CrowdStrike's distributed security platform serving global customers
Domain
Cybersecurity, Cloud Security, Application Security
Deliverable
production ML models | product features
Required skills
threat modeling (STRIDE), code review (Go/Python/Java), application penetration testing, SAST/DAST/CSPM/DSPM/ASPM tooling, cloud-native security (AWS/Azure/GCP), container security
Preferred skills
automation development, open source security contributions, adversarial emulation, AI-assisted development security
Technologies
Go, Python, Java, Docker, Kubernetes, AWS, Azure, GCP, SAST, DAST, CSPM, DSPM, ASPM
Responsibilities
Create and maintain threat models to minimize threat surface area; Review application source code for security defects; Attack applications throughout the Secure Development LifeCycle; Build integrated tools and automation for security tasks; Assist in responding to bug bounty programs and hunt for similar issues
Seniority
Senior, hands-on IC
