Remote job
Staff Application Security Engineer
Job details
About this role
Role overview Set the technical direction for application security across a large connected-operations platform that spans cloud services, internal systems, and firmware running on IoT devices. This is a senior, high-visibility role focused on defining how vulnerability management and core AppSec programs operate, scaling them through automation, and partnering deeply with engineering teams to reduce risk across a vast attack surface.
Responsibilities - Lead strategy, operation, and continuous improvement of the vulnerability management program and other core application security programs. - Drive down mean time to remediate across the vulnerability backlog as SLAs tighten. - Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware and IoT, and corporate systems. - Translate leadership strategy into a concrete technical execution plan and architectural direction for the team. - Partner with engineering teams to drive remediation, providing clear, actionable guidance and building trusted relationships. - Mentor other engineers on secure design and remediation practices and serve as a technical voice when priorities are unclear. - Communicate risk and remediation tradeoffs to engineering leadership in language they can act on. - Participate in security incident investigations involving high-profile vulnerabilities and support on-call response for critical vulnerability events.
Requirements - Significant experience leading application security and vulnerability management programs at scale. - Deep knowledge of secure design, code-level vulnerabilities, and remediation patterns across modern cloud and IoT environments. - Hands-on ability to build automation and tooling rather than relying solely on manual review. - Track record of partnering with engineering teams to drive remediation and influence outcomes without owning the relationship end-to-end. - Strong communication skills for translating technical risk into leadership-level decisions. - Comfort participating in incident response and being on call for critical vulnerability events.
Nice to have - Experience securing firmware, embedded devices, or IoT products in addition to cloud services. - Background mentoring engineers and shaping security culture across multiple product teams.
Benefits and work setup - Remote position open to candidates residing in the United States, with offices available for those who prefer in-person or hybrid work where operational needs align. - Comprehensive benefits including health and parental leave plans and a professional development stipend, with additional program details available during the hiring process.