Application Security Engineer
$100k - $258k • Palo Alto, CA
Posted 5d ago
About the job
We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies. Our team is small, highly motivated, and focused on engineering excellence, operating with a flat organizational structure where all employees are expected to be hands-on and contribute directly to the company’s mission.
Responsibilities
- Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities.
- Design and implement secure coding guidelines and best practices for development teams.
- Integrate security practices throughout the CI/CD pipeline.
- Perform threat modeling and risk assessments for applications, developing mitigation strategies.
- Manage vulnerability tracking and remediation efforts.
- Support incident response activities related to application security.
- Stay current on emerging security threats and trends in cloud-native technologies and AI.
- Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs).
- Address security concerns specific to AI and machine learning models, focusing on the OWASP LLM Top 10.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or a related field.
- 3-5 years of experience in application security, with a strong focus on code security practices.
- Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10).
- Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages.
- Experience securing CI/CD pipelines and implementing DevSecOps practices.
- Familiarity with software supply chain security and SBOM generation tools.
- Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis.
- Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10.
- Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences.
Benefits
- Equity
- Comprehensive medical, vision, and dental coverage
- Access to a 401(k) retirement plan
- Short & long-term disability insurance
- Life insurance
- Various other discounts and perks