← Back to jobs

Remote job

Senior Application Security Engineer

Backend Remote (US-based; offices in SF, Concord, Austin)

Job details

Not specified Salary
Remote (US-based; offices in SF, Concord, Austin) Eligibility
Senior Experience
Not specified Employment

About this role

Role overview A B2B real estate technology company that brings together homebuyers, sellers, lenders, title agents, and real estate agents onto a shared digital closing platform is hiring a senior application security engineer. This is a deep-technical, staff-leaning IC role on a small AppSec team: you will set technical direction and own delivery for how vulnerabilities are found, fixed, and prevented across products and cloud infrastructure, partnering daily with product engineering, infrastructure, and platform teams.

Responsibilities - Run offensive assessments including manual penetration testing, exploit development, authenticated web/API testing, and adversarial design reviews before features ship. - Lead threat modeling and secure design review for the highest-risk initiatives, and mentor engineers to do the same for their own work. - Own and evolve the AppSec tooling stack end-to-end across SAST, DAST, SCA, secret scanning, IaC scanning, and CI/CD gates, including custom rules and automation. - Harden cloud posture by reviewing AWS configurations, IAM policies, Kubernetes/EKS workloads, and network boundaries, then building guardrails that prevent regressions. - Reduce toil by writing the tools, scripts, and integrations that turn a day of triage into minutes. - Partner with infrastructure and platform on detection engineering, incident response support, and cross-cutting programs like secrets management, supply chain, and runtime security. - Set the technical bar for the AppSec team and represent the function in architecture reviews, vendor evaluations, and compliance efforts.

Requirements - Deep application security experience with both strong offensive and defensive capabilities. - Proven ability to write code for security tooling, from Burp extensions and Semgrep rules to custom integrations. - Hands-on experience securing AWS, Kubernetes/EKS, IAM, and related cloud primitives. - Track record of partnering with product engineers to land fixes without slowing delivery. - Experience mentoring engineers and raising the technical bar of a security team. - Strong communication skills for representing security in architectural and vendor reviews.

Benefits and work setup - Comprehensive health plans, 401k program, and commuter benefits. - Professional development support, parental leave, and a flexible time off policy. - Structured online onboarding, regular all-hands meetings, and internal virtual events to keep distributed teammates connected.

Skills detected in the listing

TypeScriptPythonGoRubyAWSDockerKubernetesTerraform
Detected Sep 25, 2026
Last verified Sep 25, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight