> Markdown version of [/jobs/ext/2563886-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2563886-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Starburst Inc. - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $175,000.0 - $215,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Software as a Service, Distributed Systems, Java Virtual Machine (JVM), Systems Development Life Cycle, Software Engineering, Software Vulnerability Management, Software Security, B2b Software, Information Technology, Data Management, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 24, 2026 - **Apply:** https://www.dice.com/job-detail/f122146f-c849-4c93-bf44-5c9b975e7bf4 ## About the Role * Bachelor's degree in Computer Science, Engineering, MIS, or equivalent practical experience. * 5-7 years of experience in application security, product security, software engineering with a security focus, or a related technical role. * Deep command of application and product security fundamentals, with the judgment to distinguish real exploitability from scanner noise. * Proven experience embedding security into the SDLC and getting engineering teams to actually adopt it - plus building and scaling processes that raise a program's overall maturity. * Demonstrated experience running vulnerability management for shipped software at scale, with strong knowledge of container/image security and JVM dependency and supply chain risk. * Offensive security experience and a drive to automate it: red-teaming, or threat hunting against your own products. * Threat modeling experience on distributed systems and data platforms, and a strong bias toward automation, including using AI to scale security work. * Experience in enterprise B2B software and working directly with enterprise customers on security, ideally in regulated industries such as financial services. * Experience leading and mentoring engineers. ## Description As our Senior Application Security Engineer, you'll be the technical owner of application and product security at Starburst - one person with outsized impact, backed by automation and AI rather than a large team. This is deep, hands-on engineering work: you'll build secure-by-default patterns into how our engineers design and ship, embed security controls earlier in the development lifecycle, and create the automation that lets you cover a large engineering organization. You'll get to stand up autonomous red-teaming and threat hunting against our own products, run vulnerability management across both our self-managed enterprise platform and our SaaS, and advance our software supply chain security. Because our biggest customers are global banks, you'll also be in the room with them, explaining how we secure what we ship - the kind of high-trust, high-stakes conversation that makes this work matter., If you want to make products secure by design rather than chase what's already broken, own a program end to end, and use AI to build defensive tools, this is your opportunity. You'll work closely with Engineering, Product, and the field. As a Senior Application Security Engineer at Starburst you will: * Own and mature the Application Security program, moving it from established practice to measurable, automated, and scaled across a large engineering organization. * Shift security left into the SDLC, embedding secure-by-default patterns, guardrails, threat modeling, and automated checks into design and development (including for AI-assisted development) so issues are prevented rather than found late. * Build autonomous red-teaming and threat hunting against our own products, using AI and automation to continuously probe for weaknesses instead of relying on point-in-time testing. * Own vulnerability management for everything we ship across our self-managed enterprise platform and SaaS product - container images, third-party dependencies, and first-party code - automating detection, triage, and routing, and advancing remediation through reachability/exploitability analysis and attack-surface reduction. * Own application and supply chain security tooling (SAST, SCA, DAST, container scanning), plus third-party penetration testing and the Vulnerability Disclosure Program. * Be the security voice with customers and leadership, working directly with enterprise customers on posture and assurance, and reporting on product security in executive, customer, and audit conversations. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's all about the Data](https://www.wearedevelopers.com/videos/425-it-s-all-about-the-data) - [ Your Code Is the Sales Team Now](https://www.wearedevelopers.com/videos/100327-your-code-is-the-sales-team-now) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)