> Markdown version of [/jobs/ext/1217070-staff-security-engineer-application-security](https://www.wearedevelopers.com/jobs/ext/1217070-staff-security-engineer-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Security Engineer, Application Security - **Company:** NINJATRADER, LLC - **Location:** Chicago, IL, United States (Remote available) - **Experience:** Expert - **Salary:** $210,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing, Python (Programming Language), Systems Integration, Software Vulnerability Management, Large Language Models, Software Security, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6f529f63fa9b2024 ## About the Role * 7+ years of experience in Application Security, Product Security, or Security Engineering * Strong hands-on experience with threat modeling and secure design * Experience with vulnerability management and application security tooling * Experience working in cloud-native environments such as AWS and GCP * Experience integrating security into CI/CD pipelines and developer workflows * Ability to write code in Python, Go, or similar languages for automation and tooling * Strong ability to work cross-functionally with engineering teams Bonus points for: * Experience scaling security in a high-growth or late-stage startup * Familiarity with AI-driven security workflows or automation * Background in API security, data protection, or multi-tenant systems * Experience with bug bounty programs and penetration testing * Security certifications such as CISSP ## Description We're looking for a Staff Security Engineer, Application Security to help scale and mature our security program. You'll own key security domains and initiatives end-to-end, working closely with engineering to ensure systems are secure by design. This role is highly hands-on, with opportunities to drive meaningful impact through automation, secure design, and developer enablement. You'll operate with significant autonomy while partnering with senior engineers and security leadership to scale security across the organization. In this role you will: * Own key security domains such as vulnerability management, application security, API security, and supply chain security * Drive improvements in security coverage, prioritization, and remediation workflows * Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows * Provide actionable, pragmatic guidance that helps teams ship securely * Develop and improve security tooling and automation to reduce manual effort * Implement and tune tools for SAST, SCA, DAST, dependency security, and container security * Leverage AI/LLMs where appropriate to improve triage, detection, and review processes * Triage and prioritize vulnerabilities using risk-based approaches * Partner with teams to ensure timely remediation of critical issues * Help define and improve SLAs, metrics, and reporting * Conduct threat modeling, design reviews, and security assessments * Contribute to incident response and postmortems for security events * Identify and help remediate systemic risks ## Related Videos - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)