> Markdown version of [/jobs/ext/2732725-security-engineer](https://www.wearedevelopers.com/jobs/ext/2732725-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Myfitnesspal Premium - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $90,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Github, Identity and Access Management, Mobile Application Software, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Secure Coding, Mobile Security, Software Engineering, Software Vulnerability Management, Workflow Management Systems, Autoscaling, Large Language Models, Software Security, Containerization, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Integration Frameworks, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/application-security-engineer-myfitnesspal-9898696 ## About the Role * 2-4 years of experience in security engineering, application security, software engineering, or a closely related role * Understanding of application security assessment techniques (e.g., SAST, DAST, SCA, penetration testing) and the steps to remediate findings * Knowledge of secure development practices for web and mobile applications (e.g., OWASP Top 10, OWASP MASVS) * Experience working with AI/agentic-assisted tooling (e.g., Claude Code or similar AI coding assistants, LLM-powered workflows, or agentic automation) and enthusiasm for applying it to security work * Experience performing security triage, investigation, and vulnerability management, including communicating findings and remediation guidance to engineers * Familiarity with auto-scaling cloud microservices and associated technologies (e.g., containerization, Kubernetes, infrastructure as code) * Strong communication skills, enabling collaboration across cross-functional teams, and the judgment to raise a security finding and land it as a shared problem to solve, not a fight to win * Ability to create documentation that describes technical details clearly, including for non-technical audiences * Ability & desire to learn new product lines and technologies quickly & efficiently * Education and/or certifications equivalent to BS in Computer Science or IS related field; GIAC (e.g., GWEB, GCIH), OSCP, CSSLP, Security+, or vendor-specific certifications are a plus, * Experience automating security processes (e.g., Python, SOAR platforms, workflow automation) is strongly preferred * Experience with security scanning in CI/CD pipelines and orchestration tools (e.g., GitHub Actions) is a plus * Experience operating or triaging for a bug bounty program is a plus Values you'll model * Be Kind and Care - build with empathy; assume positive intent; support teammates and members. * Live Good Health - champion healthy habits and balance in how we work and what we ship. * Be Data-Inspired - ground decisions in research and data; measure what matters. * Champion Change - lean into ambiguity; iterate, learn, and improve continuously. ## Description As a Security Engineer II, you will own the day-to-day operation of our application security vulnerability management program and act as a trusted security partner to product engineering teams. You'll triage what our tooling and researchers find, drive it to remediation, and build the automation that makes the whole program run with less manual effort. This is a hands-on technical position with real ownership and substantial opportunity for growth., * Own day-to-day application security vulnerability management: triage findings from SAST, SCA, DAST, and mobile security tooling, assign severity and due dates, propose remediations, and drive tickets through our SVM process to resolution * Operate and grow our bug bounty program - scoping engagements, triaging researcher submissions, validating findings, and coordinating with vendors * Leverage AI and agentic tooling (for example, Claude Code and agentic pipelines) to accelerate security workflows - from vulnerability triage and enrichment to automated remediation support - and help ensure our AI-assisted development practices remain secure * Build and maintain security automation (for example, in our SOAR platform and with Python) that normalizes vulnerability intake, drives notifications and SLAs, and produces the metrics and reporting that keep the program transparent * Partner with product engineering teams on remediation - joining triage and refinement discussions, answering questions, and representing security as a business enabler rather than a blocker * Perform security reviews of new features, services, and third-party integrations, providing pragmatic, risk-based guidance * Advocate secure coding practices and contribute to developer-facing security documentation and training * Administer and tune application security tooling across the SDLC, and help evaluate and implement new security technology * Support identity and access management workflows and the automation behind them ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Fifty Shades of Kubernetes Autoscaling](https://www.wearedevelopers.com/videos/813-fifty-shades-of-kubernetes-autoscaling) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)