> Markdown version of [/jobs/ext/225718-application-security-engineer-federal-us-government](https://www.wearedevelopers.com/jobs/ext/225718-application-security-engineer-federal-us-government). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - Federal / US Government - **Company:** Verkada Inc. - **Location:** San Mateo, CA, United States - **Experience:** Expert - **Salary:** $130,000.0 - $280,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Code Review, Python (Programming Language), Reliability Engineering, Cloud Services, Security Information and Event Management, Software Engineering, Software Technical Review, Software Security, Information Technology - **Published:** May 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=92a1bf53b2347689 ## About the Role Do you have experience in Triage?, Do you have a Bachelor's degree?, * Ability to successfully pass a background screening in accordance with CJIS security standards * Eligibility to onboard into AWS GovCloud production environments * Bachelor of Science in Computer Science degree or equivalent * Strong experience with AWS, GCP or other cloud service provider * 7 - 10+ years of experience as a security engineer, software engineer, site reliability engineer, or security consultant * Understanding of security weaknesses, exploits, attacks and mitigations * Experience and enthusiasm for learning about new security products, features, and strategies; * Coding ability. You will sometimes write production Python/Go code, security peer review code, build proofs of concept or implement automation scripts * Excellent collaborative skills * Outstanding written and verbal communication * Experience with most of the following: Security Development Lifecycle, Threat Modeling, Architecture Analysis, Technical Design Review, Security Code Review, Open Policy Agent, SIEM * Must be willing and able to work onsite five days per week ## Description * Facilitate the security baked into our applications throughout the software development lifecycle * Evangelize software security best practices through training and information sharing * Partner closely with engineering and product teams to improve the security of Verkada's products and exceed customers' expectations * Explore innovative solutions to enable Verkada business instead of "Security says No" * Collaborate with other engineering leaders to define, communicate, and execute on goals, priorities and process * Set up security tooling and secure defaults to ensure software security best practices * Perform architecture analysis, threat modeling and technical design reviews of sensitive features and infrastructure * Create and operate a bug bounty program * Triage and recommend solutions for security bugs from tools, third party assessments and bug bounties * Collaborate with the CISO and security team to grow the broader Verkada security program * Share your security experience with other teams internally and externally via security conferences and blogs * Help your peer engineers grow their own security reasoning and knowledge ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)