Remote job
Staff Application & Product Security Engineer
Job details
About this role
Role overview Staff-level individual contributor focused on application and product security for a Java-based software platform deployed as both SaaS and on-premise. Sets the technical direction for secure development, owns the product security posture customers experience, and partners with engineering, cloud security, and product leadership to ship secure features at scale.
Responsibilities - Own and mature the secure software development lifecycle: threat modeling, security requirements, design reviews, and policy-as-code guardrails that make the secure path the default. - Operate and tune SAST, SCA, secrets detection, container, and infrastructure-as-code scanning, building reusable secure patterns and reference implementations. - Run risk-based triage, remediation, and verification for product vulnerabilities, including remediation SLAs, escalation paths, and CVE lifecycle management. - Coordinate third-party penetration tests, reproduce externally reported issues against running product instances, and lead the vulnerability disclosure program. - Threat-model LLM-enabled features, AI agents, and AI-assisted developer workflows, applying OWASP Top 10 for LLM Applications and the NIST AI RMF. - Serve as the technical owner for customer-facing product security: triage customer scan findings, answer security RFIs, author advisories, and drive security roadmap items such as SSO/SAML upgrades and RBAC redesigns.
Requirements - 6+ years in application security, product security, or secure software engineering, with experience building or maturing an AppSec program across multiple engineering teams. - Strong proficiency in an object-oriented language, ideally Java, with the ability to read, debug, and write production-quality code across Java, TypeScript, Python, or Go. - Deep knowledge of application attack surfaces, including authentication, session management, access control, and multi-tenant isolation. - Experience running threat modeling, design reviews, manual security testing, and working with developers through remediation. - Track record of running a vulnerability disclosure program, coordinating CVEs, and producing customer-facing security advisories and hardening documentation. - Clear communication skills with the ability to translate technical risk into guidance for developers and executives and to hold a release-gating decision when needed.
Nice to have - Securing LLM applications, AI agents, or AI-assisted development tools. - SBOM tooling (CycloneDX/SPDX), VEX, artifact signing, and SLSA. - AWS, Kubernetes/EKS, Terraform, Jenkins, and tools such as Snyk, GitHub Advanced Security, Semgrep, or Burp Suite. - Familiarity with NIST CSF 2.0, OWASP SAMM/ASVS, NIST SSDF, and supporting SOC 2 or ISO 27001 audits. - Certifications such as CSSLP, OSWE, GWAPT, or AWS Security. - Background in enterprise software supporting both SaaS and customer-hosted deployments, including MFT/EDI or B2B integration products.
Benefits and work setup - Compensation range of $160,000 to $180,000 plus bonus opportunity. - Health, dental, and vision coverage, FSA and HSA options, and an Employee Assistance Program. - Flexible PTO, paid parental leave, 401(k) match, and a remote work environment.