Remote job
Application Security Engineer [Remote-US]
Job details
About this role
Role overview Join a remote-first organization as an Application Security Engineer focused on building secure-by-default products across an AI-native technology platform. You will partner closely with product and engineering teams to embed security into the software development lifecycle, identify risks early, and help applications stay resilient, scalable, and compliant. The role is well-suited for someone who wants to balance hands-on security work with cross-team influence in a fast-moving environment.
Responsibilities - Partner with product and engineering teams to integrate security considerations into application design and development from the earliest stages. - Lead threat modeling exercises using methodologies such as STRIDE or PASTA, translating findings into practical mitigations for complex systems. - Conduct secure code reviews, application security assessments, and vulnerability analyses, then drive prioritized remediation. - Develop and roll out automated security guardrails that operate throughout the software development lifecycle. - Promote secure coding practices through training, coaching, and awareness initiatives for engineers and adjacent roles. - Collaborate with security, privacy, and business assurance stakeholders on compliance and risk management objectives, and help maintain security standards and best practices that scale.
Requirements - Associate's degree or equivalent experience, with a bachelor's degree preferred. - 4–6+ years of software engineering experience, including at least 2 years focused on application security. - Familiarity with OWASP Top 10, ASVS, MASVS, and similar application security frameworks. - Working knowledge of cloud platforms and modern application architectures. - Proficiency in at least one programming language and its associated security tooling. - Strong communication skills and the ability to influence both technical and non-technical stakeholders.
Nice to have - Security certifications such as CSSLP, GWEB, or OSWE. - Background in regulated industries such as insurance, financial services, or healthcare. - Experience with mobile application security, QA testing, or penetration testing. - Familiarity with AI technologies, LLM security, or prompt engineering. - Scripting and automation experience to streamline security processes. - Active participation in the security community through conferences, mentoring, publications, or open-source contributions.
Benefits and work setup - Remote-first within the U.S.; core collaboration hours run 9 AM to 2 PM Pacific. - Medical, dental, vision, life insurance, supplemental income plans, a Headspace subscription, monthly wellness allowance, and a 401(k) with company match. - $2,000 one-time home office stipend, with a company-issued MacBook Pro shipped before day one. - Four weeks of accrued PTO in the first year and twelve weeks of fully paid parental leave for both birthing and non-birthing parents. - Up to $5,000 annually for professional learning, plus LinkedIn Learning and coaching resources. - Indicative salary range of $175,000 to $215,000, with final offers based on skills, experience, and internal structure.