> Markdown version of [/jobs/ext/2475754-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2475754-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Vcluster Labs - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Automation of Tests, Cloud Computing, Data Centers, Python (Programming Language), Machine Learning, Natural Language Processing, Role-Based Access Control, Salesforce.Com, Secure Coding, Security Software, Software Vulnerability Management, Chatbots, Software Security, Multi-Cloud, Gitlab, Containerization, Stripe, Kubernetes, Hardware Infrastructure, Vulnerability Analysis - **Published:** August 18, 2026 - **Apply:** https://www.builtincolorado.com/auth/login?destination=/job/senior-application-security-engineer/10726317 ## About the Role * Experience: You have 5+ years in Application Security or Product Security, with a strong focus on containerized environments. * Kubernetes Depth: You have a deep understanding of Kubernetes architecture, RBAC, and container runtime security. You understand the specific risks of multi-tenancy. * Code Proficiency: You are comfortable reading and writing Go, which is the language of our core product. You can spot a vulnerability in a PR without relying solely on automated tools. * Modern Tech Mindset: You thrive in fast-paced cutting-edge environments. You are excited to solve novel problems related to AI and multi-tenant infrastructure. * Cognitive Flexibility: You view feedback as a learning mechanism, not a critique, and are willing to understand the unique needs and concerns of our customers. Bonus points for: * Certifications: CKS (Certified Kubernetes Security Specialist) or OSCP. * AI/GPU Context: Experience securing AI workloads or GPU cloud infrastructure. * Automation Skills: Experience writing custom security tooling or automation scripts in Python or Go. * Documentation: A willingness to contribute to our public-facing security documentation and "Trust Center" to help our customers navigate compliance. ## Description As a Sr. Application Security Engineer at vCluster Labs, you are the architect of trust in our diverse ecosystem. In this role, you will be responsible for the end-to-end security of our product, ensuring that vCluster remains the de facto standard for secure Kubernetes multi-tenancy. You will define the security standards that allow our customers to run high-privileged workloads without fear, building in-depth strategies that span our entire codebase and infrastructure., As a Sr. Application Security Engineer, your role will include: * Core Product Security: Perform deep-dive security reviews of our core Go-based applications and Kubernetes controllers, as well as the frontend user interface. With a targeted focus on avoiding privilege escalation within our multi-tenant architecture. * Threat Modeling: Lead the threat modeling process for new features, proactively identifying risks associated with shared GPU resources and multi-cloud environments. * Automated Security: "Shift left" by continuing to integrate security checks into our CI and developer workflows. Optimizing these checks for speed, ensuring security never becomes a bottleneck for engineering velocity. Separately, you will manage automated and manual scanning of our entire product stack. * Vulnerability Management: Own the lifecycle of security vulnerabilities from discovery to remediation. You will triage both external and internal reports, drive the resolution of critical issues across the engineering organization, and communicate effectively across stakeholders. * Feature Development: Everyone at the organization contributes to both the ideas and development of new features. Many of which are directly related to security topics such as container breakouts and isolation, pushing the envelope of what's possible in constrained environments. * Developer training: Make complex topics easier to understand for all engineers, including new attack vectors and secure coding concepts., 2. Own the Outcome: We understand that our responsibility doesn't end when a task is checked off; it ends when the value is delivered. We connect our daily individual actions to the broader success of the company and our customers. 3. Create Wow: We measure success by the experience we generate, both inside and outside the company. For our customers, this means impressive speed and intuitive experiences. For our team, this means going the extra mile to support one another and to continuously drive each other to new heights. 4. Open Source, Open Mind: We are actively contributing to and maintaining open-source projects. Internally, we foster meritocracy - the strongest ideas win, no matter who or where they come from. 5. Build Tomorrow's Standards, Intentionally: We don't just ship software; we define the state-of-the-art of tomorrow. We are fearless in tearing down old approaches to build something better, but we are disciplined in how we do it because we know our users rely on our technology to run mission-critical infrastructure platforms., Artificial Intelligence * Machine Learning * Natural Language Processing * Software * Conversational AI The Account Executive will build a sales pipeline in the German markets, work with cross-functional teams, and maintain stakeholder relationships to drive sales and manage accounts for Deepgram's voice AI platform. Top Skills: AISales TechnologySpeech-To-SpeechSpeech-To-TextText-To-SpeechVoice Ai Deepgram Account Executive 15 Hours Ago Remote Mid level Mid level Artificial Intelligence * Machine Learning * Natural Language Processing * Software * Conversational AI Sell Deepgram's voice AI platform across EMEA by prospecting new logos, building pipeline, closing full-cycle technical deals, collaborating with Sales Ops and Sales Engineers, managing stakeholder relationships, and driving upsell with CSMs. Target technical buyers and communicate product value to meet and exceed quotas. Top Skills: Ai/MlCloud ApisDeveloper ToolsSpeech-To-TextText-To-SpeechVoice Ai Shield AI Senior Bid Manager 16 Hours Ago In-Office or Remote Senior level Senior level Aerospace * Artificial Intelligence * Machine Learning * Robotics * Software Lead end-to-end international and US federal government and commercial bids/proposals for EURAF GTM, manage competing priorities, drive cross-functional teams, improve proposal processes, mentor contributors, and support customer briefings, demos, and BD operations. Top Skills: Autonomy SoftwareHivemindShipleyUnmanned/Uncrewed SystemsV-BatX-Bat What you need to know about the Colorado Tech Scene With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation. Key Facts About Colorado Tech * Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey) * Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3 * Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech * Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook) * Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures * Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute ## Related Videos - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Chatbots are going to destroy infrastructures and your cloud bills](https://www.wearedevelopers.com/videos/1130-chatbots-are-going-to-destroy-infrastructures-and-your-cloud-bills) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Navigating Growth, Scaling Challenges, and Office Expansions with David Singleton, CTO at Stripe](https://www.wearedevelopers.com/videos/100362-navigating-growth-scaling-challenges-and-office-expansions-with-david-singleton-cto-at-stripe) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) ## Related Articles - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)