All open roles

Senior Application Security Engineer

Engineering · Posted 2 months ago

We are looking for a Senior Application Security Engineer with 6+ years of experience to join a small but high-impact security team and bring an engineering-first mindset to application security. You're someone who started as a software engineer or has always been hands-on with code – you read it fluently, write produc...

Way of working
Remote
Location
USA, Canada
Pay range
$150,000 to $230,000
Level
Senior
Experience
6 to 10 years
Type
Full time
Visa sponsorship
Not offered for this role
The company
200 to 1000 people

Skills that matter here

Node.jsPythonTerraformAWS

The full description

We are looking for a Senior Application Security Engineer with 6+ years of experience to join a small but high-impact security team and bring an engineering-first mindset to application security. You're someone who started as a software engineer or has always been hands-on with code – you read it fluently, write production-quality fixes, and ship them yourself rather than throwing findings over the fence. You'll help automate away manual security work using AI-native tooling so the team can scale through leverage and focus on broader security architecture. This is a rare opportunity to shape how security is built into an engineering organization that's moving fast, innovating with AI, and serving highly regulated customers.

What you will be doing

- Contributing production-quality code directly to the application (Node.js/Python) – shipping security fixes and hardening features yourself, not just filing tickets for engineers to action

- Building AI-powered automation to eliminate manual security work (e.g., PR analysis, vulnerability triage) so the team can scale faster and focus on higher-leverage architecture work

- Managing the HackerOne bug bounty program end-to-end – evaluating submissions, reproducing issues, and closing findings by shipping fixes

- Defining secure-by-design patterns and driving security standards across the application architecture, including for AI-integrated product features

- Acting as a security reviewer on RFCs and design documents, pairing with engineers to resolve issues at the source rather than blocking them

Interested in this one?

There is no apply button here on purpose. Tell us about yourself, we book a short call, and if this role fits we walk you through the company and ask before anything is sent. Always free for you.

Tell us about you
Tell us about you