Sr. Security Engineer
Core
Drive application security across the full SDLC, build internal security tooling, and partner with engineering to embed security in product development.
Role type
Senior IC Security Engineer
Builds
Internal security tooling, secure code review pipelines, and vulnerability management systems
Domain
SaaS security, cloud security, application security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application security, threat modeling, secure code review, penetration testing, vulnerability management, SAST/DAST/SCA tooling, scripting (Python/JavaScript/Go/Ruby), cloud security (AWS), container/Kubernetes security
Preferred skills
OSCP, GWAPT, GPEN, CEH certifications, AI tool optimization for security workflows
Technologies
SAST, DAST, SCA, CI/CD pipelines, AWS, GCP, OVH, Kubernetes
Responsibilities
Lead application security reviews and threat modeling; operate and improve SAST/DAST/SCA tooling; execute internal penetration tests; own the vulnerability management lifecycle; develop secure coding standards and training; integrate security tooling into CI/CD; investigate security incidents and bug bounties; partner on security architecture decisions.
Seniority
Senior, hands-on IC
