17h ago
Security Engineer, Application Security
San Francisco or NYC
$130k-$500k / year
full-timeseniorai-ml
๐ Tech Stack
๐ผ About This Role
You'll own application security at a company where the app layer is the highest-priority security surface. You'll embed in the development lifecycle, review code for exploitable flaws, build security tooling into CI/CD, and drive vulnerability remediation across a platform serving 300K+ experts. You'll use AI heavily in security work and work in-person five days a week.
๐ฏ What You'll Do
- Embed security review workflows in the SDLC
- Perform PR-level analysis for auth bugs, injection flaws, and logic errors
- Build SAST/DAST pipelines integrated into CI/CD
- Manage vulnerability prioritization based on real exploitability
๐ Requirements
- 5+ years professional experience in application security or related field
- Deep understanding of web application security (OWASP Top 10, attack chains, business logic flaws)
- Proficiency in Python, TypeScript, or Go
- Experience building or tuning SAST/DAST tooling (Semgrep, CodeQL, Snyk, Burp)
โจ Nice to Have
- Experience running or triaging a bug bounty program (HackerOne, Bugcrowd)
- Offensive security skills and penetration testing experience
- Experience securing AI/ML applications or supply chain security
๐ Benefits & Perks
- ๐ฐ Competitive compensation with equity
- ๐ข In-person collaboration in SF, NYC, or London offices
- ๐ ๏ธ Ownership of entire application security domain
- ๐ค AI-native tools for daily security work
- ๐ญ Insider perspective on frontier AI models
๐จ Hiring Process
Estimated timeline: 2-4 weeks ยท AI estimate
- 1Recruiter Callยท 30 min
- 2Technical Screenยท 60 min
- 3On-site Interviewยท 4 hours
0 0 0