Security Engineer, Application Security
Core
Own application security for a high-priority security surface platform serving 300K+ experts and enterprise clients, embedding security into the development lifecycle and using AI tools to accelerate code review and threat modeling.
Role type
Senior IC application security engineer (AI-native)
Builds
Security review workflows in SDLC, SAST/DAST pipelines in CI/CD, vulnerability management processes, secure coding standards, threat models for AI data pipelines, and bug bounty program operations.
Domain
AI data platform / Application Security
Deliverable
production ML models | product features
Required skills
Web application security (OWASP Top 10, attack chains, business logic flaws), Python/TypeScript/Go, SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp), vulnerability pipeline management, modern web frameworks/APIs/authentication patterns, production vulnerability remediation.
Preferred skills
Bug bounty program operations (HackerOne, Bugcrowd), offensive security/penetration testing, AI/ML application security (model serving, prompt injection), supply chain security, custom security tooling development, open source security contributions.
Technologies
Semgrep, CodeQL, Snyk, Burp, Python, TypeScript, Go
Responsibilities
Review code for exploitable flaws in PRs, build security tooling into CI/CD, drive vulnerability remediation, create threat models for new features, manage bug bounty program triage.
Seniority
Senior, hands-on IC
