Staff security engineer, application security
Remote • New York City, NY • FullTime
Posted 21h ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
As a Staff Security Engineer, Applications at WRITER, you will be responsible for building the security foundations that protect the AI systems powering some of the world's most recognizable brands. You will work at the intersection of application security, AI infrastructure, and developer enablement, partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy. This role involves defining how enterprise AI applications are secured, from threat modeling LLM architectures to building automated security controls that scale across the platform. You will tackle unique challenges such as securing AI agents, protecting training data pipelines, and designing controls for novel AI systems.
Responsibilities
- Build security into the AI platform by conducting threat modeling, designing secure architectures, and ensuring security considerations shape product decisions.
- Own and evolve the application security program, including establishing SAST/DAST scanning in CI/CD pipelines, conducting security code reviews, and building automation for vulnerability detection.
- Partner with engineering teams to establish and champion secure coding standards and create reusable security patterns.
- Design and recommend security features and products to secure customer environments.
- Integrate and leverage AI agents to increase velocity for the security and engineering teams.
- Lead security assessments and penetration testing of applications, AI services, and APIs, identifying and remediating vulnerabilities.
- Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents.
- Research emerging threats in AI/ML security, specifically for LLMs and generative AI, and proactively build defenses.
Requirements
- Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems.
- Understanding of developer experience and workflows for shipping features and products.
- Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to review code across multiple languages.
- Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices.
- Excellent communication skills to translate complex security concepts into clear recommendations for technical and non-technical audiences.
- A builder's mindset focused on automation, scaling, and empowerment.
Benefits
- Generous PTO, plus company holidays
- Medical, dental, and vision coverage for you and your family
- Paid parental leave for all parents (16 weeks)
- Fertility and family planning support
- Early-detection cancer testing through Galleri
- Flexible spending account and dependent FSA options
- Health savings account for eligible plans with company contribution
- Annual work-life stipends for wellness and learning and development