17h ago

Security Engineer, Application Security

San Francisco or NYC

$130k-$500k / year

full-timeseniorai-ml

๐Ÿ›  Tech Stack

๐Ÿ’ผ About This Role

You'll own application security at a company where the app layer is the highest-priority security surface. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts. You'll use AI heavily in security work and work in-person five days a week.

๐ŸŽฏ What You'll Do

  • Embed security review workflows in the SDLC
  • Perform PR-level analysis for auth bugs, injection flaws, and logic errors
  • Build SAST/DAST pipelines integrated into CI/CD
  • Manage vulnerability prioritization based on real exploitability

๐Ÿ“‹ Requirements

  • 5+ years professional experience in application security or related field
  • Deep understanding of web application security (OWASP Top 10, attack chains, business logic flaws)
  • Proficiency in Python, TypeScript, or Go
  • Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp)

โœจ Nice to Have

  • Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
  • Offensive security skills and penetration testing experience
  • Experience securing AI/ML applications or supply chain security

๐ŸŽ Benefits & Perks

  • ๐Ÿ’ฐ Competitive compensation with equity
  • ๐Ÿข In-person collaboration in SF, NYC, or London offices
  • ๐Ÿ› ๏ธ Ownership of entire application security domain
  • ๐Ÿค– AI-native tools for daily security work
  • ๐Ÿ”ญ Insider perspective on frontier AI models

๐Ÿ“จ Hiring Process

Estimated timeline: 2-4 weeks ยท AI estimate

  1. 1Recruiter Callยท 30 min
  2. 2Technical Screenยท 60 min
  3. 3On-site Interviewยท 4 hours
0 0 0