Remote job
Lead Application Security Engineer
Job details
About this role
Role overview
A high-impact Lead Application Security Engineer position focused on strengthening the security posture of large-scale applications, APIs, and AI-powered platforms. The role centers on embedding AI-native security practices and intelligent automation throughout the software development lifecycle, partnering closely with Engineering, Product, QA, DevOps, and platform teams to enable secure innovation at speed.
Responsibilities
- Conduct AI-assisted threat modeling to surface application, API, cloud, data, and machine-learning risks during design and early development. - Lead automated and AI-assisted code security reviews using SAST, DAST, SCA, secrets detection, IaC scanning, container scanning, and contextual risk analysis. - Assess third-party libraries, vendor integrations, and open-source dependencies for security, compliance, and supply-chain risk through automation and intelligent correlation. - Embed security testing and automated risk detection into CI/CD pipelines and contribute to policy-as-code guardrails, reusable controls, and intelligent security checkpoints. - Monitor emerging application, cloud, API, and AI/ML threats (including prompt injection, data poisoning, model abuse, and insecure tool use) and help design proactive defense mechanisms. - Support AI-enabled red team, blue team, and incident response simulations, and use telemetry and risk scoring to aid investigations and post-incident analysis.
Requirements
- Significant experience in application or product security engineering, including hands-on work with modern frameworks such as React, Node.js, Django, or FastAPI. - Working knowledge of securing APIs, microservices, authentication, and authorization mechanisms such as OAuth2, OIDC, JWT, and service-to-service authentication. - Experience with cloud platforms (AWS, GCP, or Azure) and containerized environments such as Docker and Kubernetes. - Familiarity with security testing and automation tools such as Semgrep, SonarQube, Burp Suite, OWASP ZAP, Trivy, Snyk, or GitHub Advanced Security. - Ability to analyze security findings, correlate risk context, and translate results into actionable remediation guidance for engineering teams. - Strong collaboration and communication skills across Engineering, Product, QA, DevOps, and Security functions.
Nice to have
- Experience building AI-assisted security workflows, automated triage systems, or risk-scoring models. - Background with policy-as-code, infrastructure-as-code security, and CI/CD governance. - Scripting and automation framework experience for security testing and remediation workflows. - Relevant certifications such as OSCP, GWAPT, CSSLP, cloud security, or AI/ML-specific security credentials.
Benefits and work setup
- Unlimited paid time off. - Medical, dental, and vision coverage. - Employee equity and employee discount programs. - Virtual wellness classes and pet insurance benefits. - Reported salary range of $220,000–$250,000 total compensation, depending on location and experience.