> Markdown version of [/jobs/ext/2385908-senior-staff-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2385908-senior-staff-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior / Staff Application Security Engineer - **Company:** Suno Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $230,000.0 - $330,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Application Layers, Systems Development Life Cycle, Secure Coding, Large Language Models, Software Security, Generative AI, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=816aa6ac9d393975 ## About the Role * 6+ years in security engineering with deep, hands-on application-security expertise. * Strong command of the vulnerability classes that cause incidents and how to eliminate them at the source - code, API, and authz design. * A builder who has stood up AppSec practices and secure-SDLC tooling, not only operated established ones. * Fluent in modern application stacks and comfortable in AWS. * Able to work shoulder-to-shoulder with engineers and raise the bar without becoming a blocker. * Able to write and ship production-quality code, not only review it. * Curiosity about emerging AI/LLM threat classes and how to defend against them as the product evolves. * Nice to have: Consumer product at scale, secure-by-design work on generative-AI or ML product surfaces, and/or early security-hire experience. ## Description We're looking for a Senior / Staff Application Security Engineer to own the security of how our product is built. You'll be the person who makes sure our code, APIs, and services are secure by design - threat-modeling the product, hardening the application layer, and building the AppSec practice from the ground up., * Execute application security end to end: threat-model features and services, and drive remediation of the most significant risks. * Secure the application layer against the vulnerabilities that matter most - injection, broken authentication and authorization, and insecure APIs. * Build and run a secure SDLC: code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing. * Harden authentication, authorization, and session/identity handling across the product. * Secure the AI-specific application surface - model and inference endpoints, prompt and input handling, and the new classes of vulnerability that come with shipping generative features. * Partner with product and platform engineering to design security in early and raise the security bar across the codebase. * Set the standard for how engineering reasons about and ships secure code. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)