CareerPlanSign in

Security Engineer, Application Security

San Francisco or NYC💼 Full-time🗓 2026-04-15 → 2026-09-25

Core

Own application security for a high-priority security surface platform serving 300K+ experts and enterprise clients, embedding security into the development lifecycle and using AI tools to accelerate code review and threat modeling.

Role type

Senior IC application security engineer (AI-native)

Builds

Security review workflows in SDLC, SAST/DAST pipelines in CI/CD, vulnerability management processes, secure coding standards, threat models for AI data pipelines, and bug bounty program operations.

Domain

AI data platform / Application Security

Deliverable

production ML models | product features

Required skills

Web application security (OWASP Top 10, attack chains, business logic flaws), Python/TypeScript/Go, SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp), vulnerability pipeline management, modern web frameworks/APIs/authentication patterns, production vulnerability remediation.

Preferred skills

Bug bounty program operations (HackerOne, Bugcrowd), offensive security/penetration testing, AI/ML application security (model serving, prompt injection), supply chain security, custom security tooling development, open source security contributions.

Technologies

Semgrep, CodeQL, Snyk, Burp, Python, TypeScript, Go

Responsibilities

Review code for exploitable flaws in PRs, build security tooling into CI/CD, drive vulnerability remediation, create threat models for new features, manage bug bounty program triage.

Seniority

Senior, hands-on IC

Sourced via ashby · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.