Remote job
Staff Application Security Engineer
Job details
About this role
Role overview
Staff Application Security Engineer driving technical direction for an application security and vulnerability management program that spans cloud services, internal systems, and firmware running on connected IoT hardware. The role blends program strategy with deep technical execution and high-visibility influence across engineering teams, with the flexibility to dive deep into critical focus areas as security priorities evolve.
Responsibilities
- Define and continuously improve the vulnerability management program and other core application security programs - Drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten - Build automation and tooling that scales vulnerability detection and response across cloud, firmware/IoT, and corporate environments - Set technical and architectural direction, translating leadership priorities into a concrete execution plan - Partner with engineering teams to drive remediation through clear, actionable guidance and trusted relationships - Mentor engineers on secure design and remediation practices and serve as a technical voice when priorities are unclear - Participate in incident investigations involving high-profile vulnerabilities and support on-call rotations for critical vulnerability response
Requirements
- Deep experience with application security and vulnerability management across cloud and connected-device environments - Track record building scalable detection and response automation rather than relying on manual, one-by-one review - Ability to translate strategic priorities into concrete technical roadmaps - Strong communication skills for explaining risk and remediation tradeoffs to engineering leadership - Experience mentoring engineers and influencing peers across multiple teams
Nice to have
- Familiarity with firmware or IoT security alongside cloud and corporate systems - Experience coordinating with technical program management on reporting and stakeholder communications
Benefits and work setup
- Fully remote position open to candidates residing in the United States - Flexible working model supporting office-based, hybrid, and fully remote arrangements depending on team needs