← Back to jobs

Remote job

Staff Application Security Engineer

Other Full-time Permanent US

Job details

$165,200—$265,500 Salary
US Eligibility
Staff Experience
Full-time Employment

About this role

Role overview

The Staff Application Security Engineer will set the overarching technical direction for application security and vulnerability management programs across a large, multi-surface environment that spans cloud services, internal systems, and firmware running on connected IoT hardware. The position blends strategic program ownership with deep technical execution, focusing on automation, faster remediation, engineering mentorship, and translating leadership priorities into clear plans that other teams can act on.

Responsibilities

- Lead the ongoing strategy, operation, and continuous improvement of the vulnerability management program and other core application security programs, defining the process rather than only executing it. - Own and drive down mean time to remediate across the vulnerability backlog as SLAs tighten. - Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate environments, replacing manual one-by-one review. - Set technical and architectural direction for the program and translate strategic priorities into a concrete execution plan for the team. - Drive remediation by building trust with engineering teams and delivering clear, actionable guidance, partnering with technical program management on reporting. - Mentor engineers on secure design and remediation practices and serve as a technical voice other teams turn to when priorities are unclear. - Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on. - Participate in security incident investigations involving high-profile vulnerabilities, assessing impact and supporting response.

Requirements

- Significant experience leading application security or vulnerability management programs at scale. - Deep familiarity with at least one major surface area such as cloud services, IoT/firmware, or corporate IT systems. - Proven ability to design and ship automation that replaces manual review workflows. - Strong communication skills for translating technical risk into guidance that leadership and engineering teams can act on. - Track record of mentoring engineers and influencing cross-functional partners without owning all relationships directly. - Hands-on experience participating in or leading security incident response.

Nice to have

- Background setting technical and architectural direction across multiple security programs simultaneously. - Experience partnering closely with technical program management on metrics and reporting.

Benefits and work setup

- Fully remote within the United States, with working hours expected in the Central or Eastern time zone. - Eligibility excludes candidates residing in the San Francisco Bay Area, New York City metro, and Washington, D.C. metro. - Relocation assistance is not provided. - Professional development stipend, comprehensive health benefits, and parental leave plans are referenced as part of the package.

Skills detected in the listing

JavaScriptPythonGoC++AWSLLM
Detected Sep 8, 2026
Last verified Sep 8, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight