Remote job
Application Security Engineer
Job details
About this role
Role overview
A mid-level Application Security Engineer is needed to take day-to-day ownership of vulnerability management for a large-scale consumer health platform used by millions. The role combines hands-on security engineering with automation, partnering closely with product engineering teams rather than acting as a blocker, and has room for ownership and growth across web and mobile codebases.
Responsibilities
- Own day-to-day application security vulnerability management: triage findings from SAST, SCA, DAST, and mobile security tooling, assign severity and due dates, propose remediations, and drive tickets to resolution. - Operate and expand the bug bounty program, including scoping engagements, validating researcher submissions, and coordinating with vendors. - Use AI- and agentic-assisted tooling to speed up security workflows such as triage, enrichment, and automated remediation support. - Build and maintain security automation (for example in a SOAR platform and Python) that normalizes vulnerability intake, drives notifications and SLAs, and produces metrics and reporting. - Partner with product engineering during triage and refinement, answering questions and representing security as a business enabler. - Perform security reviews of new features, services, and third-party integrations, providing pragmatic, risk-based guidance. - Administer and tune application security tooling across the SDLC and help evaluate new security technology.
Requirements
- 2–4 years of experience in security engineering, application security, software engineering, or a closely related role. - Understanding of application security assessment techniques (SAST, DAST, SCA, penetration testing) and how to remediate findings. - Knowledge of secure development practices for web and mobile applications (for example OWASP Top 10 and OWASP MASVS). - Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers. - Hands-on experience with AI- or agentic-assisted tooling (such as AI coding assistants or LLM-powered workflows) applied to security work. - Familiarity with auto-scaling cloud microservices and associated technologies such as containerization and Kubernetes.
Nice to have
- Experience automating security processes with Python, SOAR platforms, or other workflow automation tools. - Experience with security scanning in CI/CD pipelines and orchestration tools such as GitHub Actions. - Prior experience operating or triaging submissions for a bug bounty program.
Benefits and work setup
- Mentorship program with optional pairing for skill and career growth. - Paid parental leave and comprehensive fertility-related support. - Monthly wellness allowance, dedicated mental health days, and access to a premium fitness and nutrition platform. - Virtual learning and development library with ongoing training opportunities. - Competitive medical, dental, and vision benefits. - Retirement savings program with employer match and an annual performance bonus. - Inclusive workplace with active DEI committee and structured recognition program. - Reasonably estimated salary range of $90,000 – $130,000, depending on skills and experience.