> Markdown version of [/jobs/ext/1338060-application-security-vulnerability-discovery](https://www.wearedevelopers.com/jobs/ext/1338060-application-security-vulnerability-discovery). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security - Vulnerability Discovery - **Company:** SRM TECHNOLOGIES, INC. - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Cloud Engineering, Static Program Analysis, Code Review, Dynamic Program Analysis, Key Management, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Deployment, Software Engineering, Software Vulnerability Management, Large Language Models, Software Security, Tenable Nessus, Dropbox, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Dynamic Application Security Testing - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ede8cbbaa01b2d03 ## About the Role * Available to work until 11:00AM Pacific Standard Time (PST). * 3+ years experience in application security engineering * Strong communication skills and relationship building skills * Experience in building and scaling the Secure Development Lifecycle * Experience with handling vulnerability, and bug bounty reports * Experience partnering with cross-functional engineering and product teams * Experience triaging, validating, and prioritizing security vulnerabilities from static analysis, dynamic analysis, dependency scanning, penetration testing, or bug bounty programs. * Experience partnering with software engineering teams to drive remediation and risk reduction efforts. * Strong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.). * Experience reviewing source code and identifying security vulnerabilities in modern programming languages and frameworks. * Familiarity with security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, and vulnerability management platforms. * Experience working with cloud-native architectures and public cloud environments (AWS preferred). * Ability to evaluate security findings, distinguish signal from noise, and communicate risk-based remediation recommendations. * Familiarity with AI-assisted development workflows, AI-powered security tooling, or LLM-based security use cases is a plus. ## Description As part of the Product Security Engineering team, you'll be working to reduce overall security risk across Dropbox. We partner with engineering and product teams during each point of the software development lifecycle (SDLC) and help drive broader security initiatives across Dropbox. Product Security Engineers provide security impact by developing secure-by-default libraries and frameworks that teams across Dropbox can frictionlessly integrate into their products. They also offer their expertise on security matters through documentation and educational initiatives. Responsibilities * Triage, validate, and prioritize security vulnerabilities identified through manual reviews, automated tooling, bug bounty reports, and AI-assisted security analysis platforms. * Participate in on-call rotation to support security incident triage, perform code reviews, and address security questions. * Partner closely with engineering teams to drive remediation efforts, provide actionable guidance, and ensure timely closure of security findings based on risk and severity. * Review security-related pull requests and code changes, providing guidance on secure implementation patterns and identifying potential vulnerabilities before production deployment. * Analyze findings generated by AI-powered security agents and automation platforms, validate results, reduce false positives, and help drive remediation workflows across engineering teams. * Collaborate with Product Security Architecture and development teams to improve vulnerability detection, prioritization, and remediation processes. * Support security incident investigations and root cause analysis when vulnerabilities or application security issues are discovered. * Develop security tooling, automation, and workflows that improve security coverage and reduce manual effort for security reviews and vulnerability management. * Administer and manage vulnerability scanning tools (e.g., Tenable or similar) * Configure, optimize, and maintain scanning tools, policies, and schedules * Track and report on remediation progress, security metrics, and risk reduction initiatives across assigned engineering organizations. * Contribute to security documentation, best practices, and developer education efforts to improve secure coding practices across Dropbox. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)