Senior Software Engineer, Application Security
$200k - $400k • San Francisco • FullTime
Posted 1mo ago
About the job
Decagon is seeking a Senior Software Engineer, Application Security to lead the application security strategy and implementation for their conversational AI platform. This role involves partnering with engineering teams to embed security into AI-powered applications, protecting against application-layer threats while maintaining performance and reliability. The position offers a significant opportunity to apply deep application security expertise to AI systems and influence security practices within a growing engineering organization.
Responsibilities
- Design and implement application security controls for the AI agent platform, including secure coding, threat modeling, and vulnerability management.
- Collaborate with product engineering teams to integrate security throughout the software development lifecycle.
- Establish application security testing programs (SAST, DAST, IAST) tailored for AI applications.
- Lead security code reviews and architecture assessments, focusing on AI model integration and data handling.
- Build security tooling and automation to help developers identify and remediate vulnerabilities.
- Respond to security incidents involving application vulnerabilities and coordinate remediation efforts.
Requirements
- 5+ years of hands-on application security engineering experience.
- Expertise in secure software development practices (threat modeling, secure code review, vulnerability assessment).
- Strong software engineering background with ability to review code in languages/frameworks used in AI/ML.
- Experience implementing application security testing tools and integrating security into CI/CD pipelines.
- Knowledge of OWASP Top 10, common application vulnerabilities, and modern security frameworks.
- Proven ability to work with engineering teams to balance security and business requirements for remediation.
- Experience securing AI/ML applications, including prompt injection and adversarial input protections.
- Familiarity with large-scale, multi-tenant SaaS applications handling sensitive data.
- Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective.
- Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar.
Benefits
- Equity
- Medical, Dental, and Vision benefits
- Life Insurance and Disability Benefits
- Retirement Plan
- Parental Leave
- Fertility and family building benefits
- Monthly wellness and lifestyle stipend
- Daily lunches and snacks in the office
- Take what you need vacation policy