Application Security Engineer
Core
Offensive security engineer challenging the security of Contentsquare's SaaS products, web applications, APIs, and cloud-native services by acting as an attacker to identify and exploit vulnerabilities.
Role type
Senior IC Application Security Engineer (Offensive Security/Red Team)
Builds
Secure web applications, APIs, and cloud-native services for global SaaS customers
Domain
SaaS, Cloud Security, Web Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Offensive security testing, threat modeling, secure code review, vulnerability lifecycle management, AI/LLM security automation, security-as-code, bug bounty program management, penetration testing coordination, incident response, NestJS, Vue.js, Angular, Snyk, Datadog ASM, Google SecOps, Crowdstrike, AWS, Azure, Kubernetes, Docker, Terraform, Python, Node.js, Shell, OWASP Top 10, MITRE ATT&CK, NIST CSF
Preferred skills
Experience with high-growth SaaS environments, CTF competition participation
Technologies
NestJS, Vue.js, Angular, Snyk, Datadog ASM, Google SecOps, Crowdstrike, AWS, Azure, Kubernetes, Docker, Terraform, Python, Node.js, Shell
Responsibilities
Conduct automated security audits of global SaaS applications; Serve as a strategic security consultant for threat modeling and AppSec reviews; Perform deep-dive security code reviews and mentor developers; Architect and manage the vulnerability lifecycle; Orchestrate AI-driven security workflows using LLMs; Lead Shift-Left initiatives and security-as-code tool development; Oversee bug-bounty programs; Coordinate external penetration testing; Drive technical response to application-level security incidents
Seniority
Senior, hands-on IC
