Job Search and Career Advice Platform

Enable job alerts via email!

Staff Application Security Engineer

Webflow

Remote

GBP 115,000 - 185,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading digital experience platform company is seeking a Staff Application Security Engineer to enhance its secure development practices. This remote-first position requires 7+ years of application security experience and deep expertise in secure software design and web application security. You will collaborate with engineering teams, lead threat modeling, and manage penetration tests to protect the platform. This role includes opportunities for mentorship and shaping security strategies while aligning with business objectives.

Benefits

Company-wide bonus program
Equity in the company

Qualifications

  • 7+ years of application security experience with large-scale applications.
  • Ability to identify security design flaws and vulnerabilities.
  • Experience leading threat modeling and advanced penetration testing.

Responsibilities

  • Collaborate to secure the web application platform.
  • Champion security standards within business strategies.
  • Find and mitigate security vulnerabilities effectively.

Skills

Application security experience
Hands-on software development
Secure software design
Modern web application security
Threat modeling
Penetration testing
Mentorship
AI in security

Education

BA/BS degree or equivalent experience
Job description

At Webflow, we’re building the world’s leading AI-native Digital Experience Platform, and we’re doing it as a remote‑first company built on trust, transparency, and a whole lot of creativity. This work takes grit, because we move fast, without ever sacrificing craft or quality. Our mission is to bring development superpowers to everyone. From entrepreneurs launching their first idea to global enterprises scaling their digital presence, we empower teams to design, launch, and optimize for the web without barriers. We believe the future of the web, and work, is more open, more creative, and more equitable. And we’re here to build it together.

We’re looking for a Staff Application Security Engineer to help us level up Webflow’s secure development practices ranging from secure coding and tooling to improving procedures.

About the role:
  • Location: Remote‑first (United States; BC & ON, Canada)
  • Full‑time
  • Permanent
  • Exempt
  • Cash Compensation: Base pay ranges vary by geographic zone:
    • United States – Zone A: $175,000 – $247,000, Zone B: $164,000 – $232,000, Zone C: $154,000 – $217,000.
    • Canada (ON & BC) – CAD 199,000 – CAD 280,000.
  • Eligible for Webflow's company‑wide bonus program. Target amounts are a percentage of base salary and vary by career level.
  • Application deadline: applications accepted on an ongoing basis until position is closed and filled.
  • Reporting to: Manager, Application Security.

As a Staff Application Security Engineer, you’ll…

  • Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem.
  • Bring security best practices to the software development lifecycle.
  • Work as part of a team to champion security standards while balancing business strategies and requirements.
  • Support Webflow’s current and future compliance frameworks.
  • Find security vulnerabilities through grey‑box techniques, and propose solutions at the architecture and code level to mitigate findings.
  • Contribute code and architecture improvements to enable security within Webflow’s application for engineers.
  • Cross‑train entry and mid‑level application security engineers.

In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we’ll help you incorporate them into your role.

About you:

Requirements:

  • BA/BS degree or equivalent experience.

You’ll thrive as a Staff Application Security Engineer if you:

  • You bring 7+ years of application security experience, including hands‑on software development, and have operated as a technical authority in securing high‑complexity, large‑scale applications.
  • You have deep expertise in secure software design, secure coding, and modern web application security, with a proven ability to identify security design flaws and complex business‑logic vulnerabilities, and to drive risk‑based remediation with engineering teams.
  • You regularly lead threat modeling efforts, conduct and oversee advanced penetration testing, and manage third‑party pentests, ensuring findings are clearly documented, communicated, and remediated to completion.
  • You have designed, implemented, and evolved software supply chain security programs, and have owned or led bug bounty programs and major security tooling initiatives, shaping strategy rather than acting solely as a contributor.
  • You have implemented and improved Secure Development Lifecycle (SDLC) processes at scale, including planning, automation, and cross‑org communication, influencing how multiple teams build and ship software securely.
  • You have driven multi‑quarter application security roadmaps and complex security programs, partnering with engineering, product, and platform teams to deliver durable security outcomes.
  • You have led security initiatives within large‑scale solutions, including designing and delivering security features directly into applications (e.g., authorization models, security controls, or admin‑level protections) in close collaboration with engineering and partner orgs.
  • You have experience using and building security solutions that leverage agentic AI, including applying AI coding agents to scale security reviews, detection, and automation responsibly.
  • You have participated in and led response efforts for application security incidents, from triage and containment through remediation and post‑incident improvements.
  • You actively mentor and elevate other application security engineers, and help foster strong security practices and judgment across engineering organizations.
  • You are passionate about security, continuously learning, and able to clearly explain complex security concepts to technical and non‑technical partners to drive alignment and action.
  • Stay curious and open to growth — actively building fluency in emerging technologies like AI to unlock creativity, accelerate progress, and amplify impact.
Our Core Behaviors:
  • Build lasting customer trust. We build trust by taking action that puts customer trust first.
  • Win together. We play to win, and we win as one team. Success at Webflow isn’t a solo act.
  • Reinvent ourselves. We don’t just improve what exists, we imagine what’s possible.
  • Deliver with speed, quality, and craft. We move fast because the moment demands it, and we do so without lowering the bar.
  • Ownership in what you help build. Every permanent Webflower receives equity (
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.