Application Security Engineer

Jobot
San Francisco, CA, United States
about 2 months ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$104,000.0 - $166,400.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software System Penetration Testing User Authentication Microsoft Azure Burp Suite Cloud Computing Security Cloud Engineering Code Review
+23 more
Continuous Integration Github Python (Programming Language) OAuth Open Source Technology Open Web Application Security JSON Web Token Security Assertion Markup Language (SAML) Secure Coding Software Engineering TypeScript Large Language Models Software Security Git GWAPT Containerization Gitlab-ci Software Coding Jenkins Static Application Security Testing Golang Programming Languages Dynamic Application Security Testing

Job description

  • Perform application security assessments including manual code review, SAST, DAST, SCA, and targeted penetration testing.
  • Lead threat modeling sessions for new features, architectural changes, and AI/LLM-backed workflows with customer product and engineering teams.
  • Integrate security tooling (Semgrep, Snyk, CodeQL, GitHub Advanced Security, Burp Suite) into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins) with minimal developer friction.
  • Triage, track, and drive remediation of findings across web, mobile, and API surfaces with developer-friendly workflows and SLAs.
  • Design and maintain secure coding standards, authentication and authorization patterns (OAuth 2.0, SAML, JWT), and training materials for customer development teams.
  • Evaluate third-party libraries, vendor integrations, and open-source dependencies for supply chain and security risk.
  • Support incident response activities and contribute to post-incident analysis with a focus on application-layer root cause.
  • Write and maintain documentation, runbooks, and architecture decision records (ADRs) for AppSec tooling, coding standards, and remediation playbooks.

Requirements

  • 3 to 5 years of experience in application security, penetration testing, or secure software development.
  • Strong knowledge of OWASP Top 10, CWE, and common web and API vulnerability classes.
  • Hands-on experience with at least two of the following: SAST, DAST, SCA, or IAST tools in real CI/CD environments.
  • Proficiency in one or more programming languages (Python, Go, JavaScript/TypeScript, or Java) for automation, tooling, and integration work.
  • Familiarity with modern development workflows including Git, CI/CD pipelines, and containerized environments.
  • Solid understanding of authentication and authorization frameworks (OAuth 2.0, SAML, JWT).
  • Excellent communication skills with the ability to translate security findings into actionable engineering tasks.
  • Must be located in the SF Bay Area or willing to travel to our San Francisco office on a regular cadence.

NICE TO HAVE

  • Relevant certifications such as OSCP, GWAPT, CEH, or CSSLP.
  • Experience with bug bounty programs or responsible disclosure processes.
  • Familiarity with cloud-native security (AWS, GCP, or Azure) and cloud-native workload protection.
  • Prior contributions to open-source security tooling.

Benefits & conditions

  • Competitive Compensation
  • Work on incredible projects that are fun and challenging
  • Full Benefits (Medical, Vision, Dental)
  • 401k
  • Long term Contract to Hire opportunity

About the company

We are a Software Consulting firm working with enterprise and start companies that are AI driven and we are developing some of the most cutting edge software/security solutions platforms in the world

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobot.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all