Senior/Staff Engineer, Application & Product Security
Accountabilities: Champion a secure-by-default culture by embedding defense-in-depth principles into engineering frameworks, architecture, and everyday development practices.
Develop security requirements for applications and services and partner directly with engineering teams to incorporate them into the software development lifecycle.
Conduct hands-on source-code reviews and investigations to develop a deep understanding of applications, architectures, and potential attack paths.
Drive the application and product security roadmap in collaboration with product leadership, engineering, and the broader security organization.
Partner closely with product, engineering, DevOps, and services teams to enable secure software delivery without unnecessarily slowing development.
Design and implement practical solutions to remediate vulnerabilities, mitigate security risks, and strengthen application defenses.
Research relevant threats, attack techniques, and emerging security risks, including those affecting AI and agent-based product capabilities.
Conduct security risk assessments, penetration testing, and threat modeling across products and services.
Translate security findings into actionable recommendations, secure coding guidance, and educational resources for engineering teams.
Build automation, frameworks, and services that eliminate repetitive security work and create scalable security capabilities.
Prioritize security initiatives according to business and technical risk rather than relying solely on vulnerability volume or automated tooling output.
Collaborate with stakeholders across the organization to continuously improve security processes, architecture, and engineering practices.
Requirements:
6+ years of professional experience in application security, product security, or a closely related security engineering discipline.
Strong software development skills, with the ability to write production-quality code and automate repetitive security tasks.
Experience building security frameworks, services, or automation that address practical application security challenges.
Hands-on experience with microservice architectures and modern software development environments.
Demonstrated ability to investigate source code and develop a deep technical understanding of complex applications and codebases.
Strong knowledge of application security principles, secure software development practices, vulnerability management, threat modeling, and penetration testing.
Experience working with security testing and development lifecycle concepts such as SAST, DAST, SBOMs, and related tooling, with the judgment to go beyond tool-generated findings.
Ability to prioritize security work based on meaningful risk, business impact, exploitability, and realistic threat scenarios.
Strong collaboration skills and experience partnering effectively with security, engineering, product management, DevOps, and service teams.
Ability to communicate technical security risks and recommendations clearly to both technical and non-technical stakeholders.
Strong product mindset, with an interest in understanding how products actually function and how security can enable rather than obstruct them.
Comfortable operating in a fast-moving environment where priorities evolve and hands-on execution is expected.
Ability to balance strategic security thinking with detailed technical implementation and problem solving.
Benefits:
Hybrid compensation: $217,000–$288,000 USD annually.
Fully remote compensation: $182,000–$240,000 USD annually.
Compensation varies based on relevant experience, qualifications, and working location.
Choice of fully remote work or hybrid work from designated U.S. hub locations.
Hybrid employees work onsite three days per week, Tuesday through Thursday.
Company-sponsored medical, dental, vision, life, and disability coverage.
No-cost access to therapy through the company’s mental health platform for U.S. employees.
Retirement savings programs and equity opportunities.
Flexible time off, paid holidays, and a company-wide winter break.
Up to 18 weeks of paid parental leave plus a stipend for a new child.
Dedicated weekly time for mental health and personal self-care.
Annual wellness and professional development stipend.
Pre-tax commuter benefits for employees working from hub locations.
Home-office support and meal benefits for remote and hub-based employees.
Additional wellness benefits, including wellness memberships, virtual care, pet insurance discounts where available, and global travel assistance.
Travel approximately 2–3 times per year for company or department offsites.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1