> Markdown version of [/jobs/ext/1340282-application-security-design-reviews-threat-modelling](https://www.wearedevelopers.com/jobs/ext/1340282-application-security-design-reviews-threat-modelling). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security - Design Reviews Threat Modelling - **Company:** SRM TECHNOLOGIES, INC. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Applications Architecture, User Authentication, Cloud Computing, Key Management, Open Web Application Security, Systems Development Life Cycle, Software Engineering, Data Streaming, Systems Architecture, Software Security, Dropbox, Programming Languages - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ee8bc3f1d4db104f ## About the Role * Available to work until 11:00AM Pacific Standard Time (PST). * 5+ years of experience in Application Security, Product Security, or a related field. * Strong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.). * Experience participating in security reviews, threat modeling exercises, architecture discussions, or application security assessments. * Strong technical writing skills and experience creating documentation and guidelines. * Strong communication skills and ability to explain security concepts to engineers with varying levels of security expertise. * Experience working collaboratively with software engineering teams to identify and address security risks. * Familiarity with cloud platforms and modern application architectures (AWS preferred). * Ability to assess risk, prioritize issues, and provide practical security recommendations. * Experience reading and understanding source code in one or more modern programming languages. * Experience building scripts, tools, or automation to improve engineering or security workflows. ## Description As part of the Product Security Architecture team, you'll help reduce security risk across Dropbox by partnering with engineering and product teams throughout the software development lifecycle (SDLC). Our team focuses on security threat modeling, and consulting. We work closely with product and infrastructure teams to identify security risks early in the design process, provide practical security guidance, and help teams build secure systems. We also develop tooling, documentation, and automation that improve the efficiency and scalability of security reviews across Dropbox. This role is ideal for a security engineer who enjoys solving technical problems, collaborating with engineers, and helping teams make informed security decisions. Responsibilities * Participate in security design reviews and threat modeling exercises for new products, services, and platform capabilities. * Partner with engineering teams to identify security risks and recommend practical mitigations during the design and development process. * Serve as a security consultant for product and engineering teams, answering security questions and providing guidance on secure implementation patterns. * Review application and system architectures, technical designs, data flows, and deployment models to identify security risks and recommend secure design patterns * Partner with engineering teams developing AI and machine learning features to identify emerging security risks and recommend secure implementation patterns. * Help maintain and improve security standards, guidance, reference architectures, and internal documentation. * Develop or enhance tooling and automation that improve the efficiency of threat modeling, security reviews, and risk assessment processes. * Collaborate with other Product Security engineers to perform application security assessments and investigate security concerns identified during development. * Contribute to developer education efforts through documentation, office hours, workshops, or security awareness initiatives. * Support security incident investigations and root cause analysis when application security issues are discovered. ## Related Videos - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [Pragmatic Blockchain Design Patterns: Integrating Blockchain into Business Processes](https://www.wearedevelopers.com/videos/1579-pragmatic-blockchain-design-patterns-integrating-blockchain-into-business-processes) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)