> Markdown version of [/jobs/ext/2733056-senior-software-engineer-security](https://www.wearedevelopers.com/jobs/ext/2733056-senior-software-engineer-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, Security - **Company:** SnapCommerce Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $128,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Burp Suite, Mobile Application Development, Cloud Computing, Cloud Computing Security, Cursor (Graphical User Interface Elements), DevOps, Elasticsearch, Python (Programming Language), PostgreSQL, Open Source Technology, Systems Development Life Cycle, Redis, Secure Coding, Mobile Security, Software Engineering, TypeScript, AI Infrastructure, Datadog, ReactJS, Amazon ElastiCache, Istio, Large Language Models, Snowflake, Software Security, Fastapi, Kubernetes, Maintaining Code, Apache Kafka, Devsecops, Microservices - **Published:** September 5, 2026 - **Apply:** https://arc.dev/remote-jobs/j/redirect/phpygsdqfy ## About the Role * 5+ years working in security (AppSec, DevSecOps, offensive security, or similar) * Professional offensive security experience, with a proven ability to find, chain, and exploit complex vulnerabilities in applications and infrastructure * Track record of leading security initiatives and mentoring or developing other engineers * Experience leading threat modeling and secure design across engineering projects * Experience designing and embedding security across CI/CD pipelines and the SDLC * Hands-on cloud infrastructure or cloud security experience (AWS, Kubernetes) * Comfortable writing and maintaining code (Python preferred) * Strong communicator who can influence and drive security work across engineering, DevOps, and leadership, * Relevant security certifications (e.g., Burp Suite Certified Practitioner, KCSA, AWS SCS, or similar) * Professional software development experience * Published security research, CVEs, or conference talks * Experience applying AI/LLMs to security or engineering workflows * Open-source security tool development or contributions * Mobile development or mobile security experience ## Description As a Senior Software Engineer on our Security team, you'll help shape the direction of our security tooling and AppSec practices and lead high-impact security work across the company. Your work spans offense and defense: hardening how our products are designed and built, breaking them to surface what matters, and building the tooling and AI that let engineers move fast without creating risk. You'll report to our Staff Software Engineer - Security and work closely with product engineers, DevOps, and Fraud. Expect high autonomy, frequent collaboration, a fast pace, and reliance on your own initiative. You'll take security initiatives end-to-end, mentor other engineers, and raise the bar for security practices across engineering. What You'll Be Working On * Help shape the technical direction of our security tooling and AppSec practices * Lead secure design across major engineering projects, from threat modeling through architecture * Design and evolve our DevSecOps architecture, deciding how security is embedded across the SDLC * Build and extend the in-house security tooling and find new and innovative ways to identify and remediate issues * Identify and implement new ways to use AI to automate and scale our security work * Perform advanced offensive security work, chaining vulnerabilities and building proofs of concept that demonstrate real business impact * Enable developers to write more secure code and ship security work faster via training and AI-powered tooling * Mentor and develop engineers on the team, and set the bar for what good security work looks like, * Services are authored as K8s-based microservices powered by Python FastAPI backends and Typescript React front-end code. * Apps are built upon Postgres, Redis, Kafka, Elasticsearch, and Snowflake. * Our infrastructure runs on AWS and leverages hosted infrastructure technologies such as EKS, MSK, Elasticache, and RDS. We use Istio for service mesh, Helm, TF and Crossplane for IAC, and Kyverno for policy-as-code enforcement. * Vulnerabilities are managed through in-house, AI-native custom tooling that you'll contribute to. We orchestrate open-source tools through this custom platform. * Security and application logs/metrics/events are managed through Datadog * Our security stack is currently evolving as we select and quickly roll out new tools. You'll play a key role in the selection and deployment of these. * As an AI-First engineering organization, we leverage modern AI development workflows using tools such as Cursor, Claude, and internally built AI agents to accelerate implementation and iteration across our codebases. You'll own and advance our AI infrastructure in this role. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 139 - Soft and hard queries](https://www.wearedevelopers.com/magazine/487-dev-digest-139-soft-and-hard-queries) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss)