> Markdown version of [/jobs/ext/2714928-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2714928-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** SHEIN --- - **Location:** Los Angeles, CA, United States - **Salary:** $91,000.0 - $149,600.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cyber Security, White-Box Testing, Mobile Application Software, Open Web Application Security, Red Team (Cyber Security), Web Applications, Large Language Models, Software Security, GWAPT, Information Technology, Blue Team (Cyber Security), Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-shein-9003623 ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent practical experience). * Solid understanding of the OWASP Top 10 and common web/mobile application vulnerabilities. * Hands-on experience with web application vulnerability assessments and penetration testing. * Familiarity with bug bounty platforms (e.g., HackerOne, Bugcrowd) and triage workflows. * Strong communication skills; ability to translate technical findings into clear remediation guidance., * Professional proficiency in Mandarin Chinese (to collaborate effectively with global / Chinese-speaking teams). * Relevant certifications such as OSCP, GWAPT, or similar. Experience with AI/LLM security testing and security automation. * Experience coordinating third-party pentest vendors and managing remediation lifecycles. ## Description We are seeking a hands-on Application Security Engineer to join our Security Engineering team in Los Angeles. You will play a key role in safeguarding our products and infrastructure by running our bug bounty program, coordinating third-party penetration testing, handling internal security requests, participating in red/blue team exercises, and helping shape our emerging AI security practices., * Bug Bounty Program Management: Operate and manage our public/private bug bounty programs on platforms such as HackerOne, including triaging incoming reports, interfacing with security researchers and triage teams, validating vulnerabilities, and driving remediation with engineering teams. * Third-Party Penetration Testing: Coordinate and manage engagements with external penetration testing vendors, scope assessments, review deliverables, and track remediation to closure. * Internal Security Testing Tickets: Own and execute internal security testing requests (tickets), including web/mobile application vulnerability assessments (black-box, grey-box, and white-box). * Red Team / Adversarial Exercises: Participate in offensive and defensive security exercises (attack & defense drills) to strengthen our overall security posture. * AI Security: Contribute to AI/LLM application security efforts, including LLM security testing, AI-assisted security automation, and assessing emerging AI-related threats. * Provide actionable remediation guidance and clear communication to engineering teams, security leadership, and stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [WebXR: Enabling Virtual and Augmented Reality on the Web](https://www.wearedevelopers.com/videos/965-webxr-enabling-virtual-and-augmented-reality-on-the-web) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)