Remote job
Staff Application Security Engineer
Job details
About this role
Role overview
A Staff Application Security Engineer is needed to own the application security strategy for how an internet-intelligence platform builds and ships software. The role sits on the Infrastructure and Operations Platform (SRE) team and is responsible for designing secure paths, guardrails, and automation that allow engineers to develop and deploy confidently across Kubernetes and Google Cloud. It is a hands-on technical leadership position covering infrastructure-as-code, container security, CI/CD pipeline integration, and the security of AI/ML-enabled services.
Responsibilities
- Drive the AppSec/DevSecOps program roadmap, embedding shift-left practices and paved roads into the SDLC rather than relying on gates. - Build and maintain DevSecOps tooling on Kubernetes and GCP, including support for AI/ML workloads. - Integrate security scanning, secret detection, software composition analysis, and infrastructure policy enforcement into CI/CD pipelines without slowing teams down. - Deliver hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load. - Set the security architecture direction for AI/ML workflows, including access control, artifact validation, input/output sanitization, and model provenance tracking. - Partner with corporate security on SOC 2 and ISO27001 audit readiness and BCDR tooling improvements. - Provide technical leadership through design reviews, threat modeling, mentorship, and shared on-call rotation with SRE.
Requirements
- 10+ years in security engineering, DevSecOps, SRE, or related roles with a track record of leading cross-team security initiatives. - Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections such as Helm or Crossplane. - Strong experience with AppSec tooling (dependency scanning, static analysis, policy enforcement) integrated into CI/CD pipelines such as GitHub Actions and ArgoCD. - Solid grasp of attacker tactics, techniques, and procedures and familiarity with relevant security frameworks.
Nice to have
- Background operating within a security-product organization where internal standards mirror external customer expectations. - Experience using AI assistants and coding agents responsibly to accelerate secure development workflows.