> Markdown version of [/jobs/ext/737734-security-engineer-application-security](https://www.wearedevelopers.com/jobs/ext/737734-security-engineer-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Application Security - **Company:** Serval, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $200,000.0 - $325,000.0 - **Contract:** Permanent contract - **Skills:** Code Review, Cyber Security, Continuous Integration, Fuzz Testing, Key Management, Systems Development Life Cycle, Web Application Security, Software Engineering, Systems Architecture, Software Vulnerability Management, Software Security, Production Code, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0b0f879d36452b27 ## About the Role Do you have experience in Web Application Security Testing?, * Have 10+ years in cybersecurity with deep expertise in application security, secure software development, and vulnerability management. * Have deep experience building and leading application/product security, secure-SDLC, and vulnerability-management functions. * Have stellar leadership skills and a demonstrated history of driving durable, continuous improvements to programs, processes, and people. * Have strong software engineering fundamentals and can read, write, and review production code, partnering with engineers as a peer rather than a gatekeeper. * Have exceptional written and verbal communication skills, can remain calm under pressure, and can effectively influence engineering and product decisions across a diverse gamut of teams, expertise, and seniority. * Have deep expertise in modern application security tooling and primitives (SAST, DAST, SCA, secrets detection, fuzzing, software supply-chain security) and in secure cloud-native and distributed-systems architecture. * Understand modern adversary tradecraft (TTPs) and how application-layer weaknesses are exploited, and have demonstrated experience translating that into practical secure-design guidance and prioritized remediation. * Are mission-oriented, have unimpeachable integrity, and are passionate about building secure software in a highly complex, fast-paced environment. Bonus points if you're excited about the security challenges unique to AI agents. ## Description As Application Security Lead, you'll build and scale the foundations of Serval's product and application security program. You will set the strategy and drive execution for secure software development, vulnerability management, threat modeling, and security architecture across our platform and the agentic systems our customers trust us to run inside their most sensitive environments. You'll be a hands-on leader with deep technical credibility and strong engineering instincts. You will build and mentor a team, partner closely with Engineering and Product, and ensure that security is designed into the systems that power Serval from the first line of code rather than bolted on later. What You'll Do * Design, implement, and operate Serval's application security program, including secure SDLC practices, threat modeling, secure design review, code review, and remediation of vulnerabilities across our services, agent platform, integrations, and customer-facing surfaces. * Build, lead, and directly mentor a team spanning product security, secure software development, and vulnerability management, hiring and scaling these functions deliberately and proportionately as Serval's platform and customer footprint grow. * Establish world-class engineering rigor through secure coding standards, paved-path libraries and frameworks, security design patterns that scale security expertise across the engineering organization. * Improve security coverage and signal quality by building and tuning the automated tooling that catches issues early (SAST, DAST, SCA, secrets scanning, dependency and supply-chain controls, and CI/CD security gates) and by partnering with engineering to make findings reliable, actionable, and low-friction to fix. * Own the vulnerability lifecycle end-to-end: intake from internal testing, researchers, and bug bounty; triage and severity assessment; SLAs and remediation tracking; and coordinated disclosure. * Partner deeply across Engineering, Product, and Infrastructure to embed security into Serval's systems by design, driving strong authentication and authorization, tenant isolation, data protection, secrets management, and the security of the agentic, tool-using workflows at the heart of the platform. * Build a security program capable of withstanding sophisticated adversaries, including by tackling the novel application-security challenges of agentic AI (prompt injection, unsafe tool use, data exfiltration, and abuse of autonomous actions) and by using Serval's own agents to solve frontier security problems. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Mutation Testing and Fuzzing in C#](https://www.wearedevelopers.com/videos/703-mutation-testing-and-fuzzing-in-c) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)