AppSec Security Engineer
Core
Build, mature, and scale an application security program by embedding with product and engineering teams to secure third-party SaaS and home-grown applications.
Role type
Senior IC Application Security Engineer
Builds
Secure CI/CD pipelines, custom security tooling, and foundational security controls for cloud and container environments.
Domain
Cybersecurity / Cloud Infrastructure / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SAST/SCA/DAST tooling, CI/CD pipeline integration, Infrastructure as Code (Terraform, Helm, Kustomize), Kubernetes security, Azure security, Threat modeling, API security design review, Security automation/scripting, OWASP standards knowledge, Software supply chain controls
Preferred skills
OPA/Gatekeeper or Kyverno policy authoring, Advanced cloud and AI security certifications
Technologies
GitHub Actions, GitLab CI, Azure DevOps, Jenkins, Terraform, Helm, Kustomize, Azure, Kubernetes, OIDC, Artifact registries
Responsibilities
Embed SAST, SCA, DAST, and secret detection tools into CI/CD pipelines; Develop secure IaC patterns; Integrate AI agents for security review assistance; Lead security design and threat modeling sessions; Review API designs for authentication anti-patterns and injection risks; Define and validate security controls for Azure and Kubernetes; Establish and maintain SAST/DAST scanning processes; Partner with engineering to remediate vulnerabilities and drive secure coding practices
Seniority
Senior, hands-on IC