Stand out for this role — generate a tailored resume and cover letter in about a minute.
Faire is seeking an Application Security Engineer to join our Engineering organization. You will help secure our marketplace by finding and fixing vulnerabilities in first‑party and third‑party code, integrating AI‑powered detection and guardrails into the SDLC.
You will lead threat modeling, security reviews for new products, and collaborate with product teams to bake in secure design. Strong experience with SAST/DAST/SCA, cloud environments (AWS/GCP), and clear risk communication is essential.
Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generatedExperience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closedA passion for coding and solving security problems scalably with code and automation, rather than with process and policyComfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes itExperience leading threat models on systems you did not build, and the judgement to know which designs need one and which do notExposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourselfA thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual findingHands‑on experience integrating security into the software development lifecyclePractical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the resultsThe ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gateExperience working in modern cloud computing environments such as AWS or GCP