Senior / Staff Application Security Engineer
ABOUT THE ROLE
We’re looking for a Senior / Staff Application Security Engineer to own the security of how our product is built. You’ll be the person who makes sure our code, APIs, and services are secure by design — threat-modeling the product, hardening the application layer, and building the AppSec practice from the ground up.
WHAT YOU’LL DO
- Execute application security end to end: threat-model features and services, and drive remediation of the most significant risks.
- Secure the application layer against the vulnerabilities that matter most — injection, broken authentication and authorization, and insecure APIs.
- Build and run a secure SDLC: code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.
- Harden authentication, authorization, and session/identity handling across the product.
- Secure the AI-specific application surface — model and inference endpoints, prompt and input handling, and the new classes of vulnerability that come with shipping generative features.
- Partner with product and platform engineering to design security in early and raise the security bar across the codebase.
- Set the standard for how engineering reasons about and ships secure code.
WHAT YOU’LL NEED
- 6+ years in security engineering with deep, hands-on application-security expertise.
- Strong command of the vulnerability classes that cause incidents and how to eliminate them at the source — code, API, and authz design.
- A builder who has stood up AppSec practices and secure-SDLC tooling, not only operated established ones.
- Fluent in modern application stacks and comfortable in AWS.
- Able to work shoulder-to-shoulder with engineers and raise the bar without becoming a blocker.
- Able to write and ship production-quality code, not only review it.
- Curiosity about emerging AI/LLM threat classes and how to defend against them as the product evolves.
- Nice to have: Consumer product at scale, secure-by-design work on generative-AI or ML product surfaces, and/or early security-hire experience.
PERKS & BENEFITS FOR FULL-TIME EMPLOYEES
- Company Equity Package
- 401(k) with 3% Employer Match & Roth 401(k)
- Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options)
- 11 Paid Holidays + Unlimited PTO & Sick Time
- 16 Weeks of Paid Parental Leave
- Creative Education Stipend
- Generous Commuter Allowance
- In-Office Lunch (5 days per week)
Additional Notes:
- Applicants must be eligible to work in the US.
- This role requires working onsite at one of our three offices.
COMPENSATION:
- $230,000 to 330,000