Remote job
Staff Application Security Engineer
Job details
About this role
Role overview
Lead application security and vulnerability management for a large-scale connected operations platform that processes trillions of data points each year across IoT hardware, cloud services, and internal systems. The Staff-level position sets the overarching technical direction across a broad attack surface while retaining flexibility to dive deep into critical focus areas as priorities evolve. The role is remote within the United States and carries high visibility, on-call responsibility, and significant cross-team influence.
Responsibilities
- Define and continuously improve the strategy and operation of the vulnerability management program and other core application security programs, rather than only executing against an existing process. - Own and reduce mean time to remediate across the vulnerability backlog as service-level expectations tighten. - Build and champion automation and tooling that scale detection and response across cloud, firmware/IoT, and corporate systems. - Set technical and architectural direction, translating leadership strategy into an execution plan for the team. - Drive remediation by partnering with engineering teams and providing clear, actionable guidance, collaborating with technical program management on reporting. - Mentor engineers on secure design and remediation, serving as a technical voice when priorities are unclear. - Communicate risk and remediation tradeoffs to engineering leadership and participate in incident investigations involving high-profile vulnerabilities, including periodic on-call duty.
Requirements
- Significant experience leading application security or vulnerability management programs at scale. - Strong track record of building automation and tooling for vulnerability detection and response across diverse environments such as cloud, firmware, and corporate IT. - Ability to set technical and architectural direction and translate strategic priorities into concrete plans. - Demonstrated skill in building trust with engineering teams and influencing remediation through partnership. - Excellent communication of risk and tradeoffs to engineering leadership in actionable terms. - Comfort with on-call responsibilities and participation in security incident response.
Nice to have
- Experience securing firmware, IoT devices, or other hardware-adjacent systems. - Familiarity with cross-cloud architectures and securing hybrid corporate environments.
Benefits and work setup
- Remote position open to candidates residing in the US. - Flexible working model that supports in-person, hybrid, and fully remote arrangements depending on role needs. - Professional development stipend and comprehensive health and parental leave plans.