App Sec Engineer

TEEMA

San Francisco (CA)

On-site

USD 207,000 - 344,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

TEEMA in San Francisco seeks an App Sec Engineer to own the secure SDLC end-to-end. You will model threats, review designs and code, and coordinate internal and external pentests to drive findings to closure.

You will build SAST/DAST/SCA tooling integrated with CI/CD, remediate vulnerabilities across bug bounty programs and internal scans, and mentor engineers on secure coding practices while shaping the security roadmap.

Qualifications

  • 4+ years in application security or software security engineering.
  • Ability to write production-grade code and produce actionable findings.
  • Deep knowledge of OAuth 2.0, OIDC, SAML, and session management.
  • Experience with AWS and containerized environments (Kubernetes, Docker).

Responsibilities

  • Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews.
  • Run and coordinate app pentests and drive findings to closure.
  • Build and own SAST/DAST/SCA tooling wired into CI/CD for secure delivery.
  • Triage and remediate vulnerabilities from various sources.

Skills

Production code
OAuth 2.0
OIDC
SAML
AWS
Kubernetes
Docker

Tools

Go
TypeScript
React
PostgreSQL
Redis
GraphQL

Job description

Job Title: App Sec Engineer
Job ID: 90238
Location: San Francisco, California

What you will be doing
  • Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews — you set the bar
  • Run and coordinate app pentests (internal and external) and drive findings to closure
  • Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code
  • Triage and remediate vulnerabilities from every angle — bug bounty, internal scans, the works
Software Security Engineering
  • Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows
  • Own the Auth0 Opal integration — tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)
  • Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good
  • Create shared libraries that make the secure path the easy path for every product engineer
Incident Response & Cloud Security
  • Be first on the scene for security incidents: investigate, contain, find the root cause, fix it
  • Partner with Infra on cloud hardening — AWS IAM, EKS, KMS, network segmentation
  • Level up detection and response by writing detection rules and improving logging and alerting
Security Culture
  • Mentor engineers on secure coding, common vuln patterns, and security architecture — you make the org smarter
  • Help set the security roadmap by grounding it in real product risk
  • Be the security teammate engineers want to work with — a collaborator, not a bottleneck
What you must have
  • Have 4+ years in application security or software security engineering
  • Actually write production code — findings reports are the floor, not the ceiling
  • Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle
  • Are comfortable in AWS and containerized environments (Kubernetes, Docker)
  • Bonus points for familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL
  • Have led complex, cross-functional security initiatives from kickoff to completion
  • Have run or participated in external pentests and seen findings through remediation
  • Thrive on ownership and ambiguity — you’d rather write the playbook than wait for one

Salary/Rate Range: $150.00 – $250.00

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Other
Other

Torsap Thai Kitchen • San Francisco (CA)

On-site
USD 140,000 - 190,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Application Security Engineer
Application Security Engineer

Talentify • Philadelphia

On-site
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Security Engineer - Application Security (Senior)
Security Engineer - Application Security (Senior)

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Security Engineer
Security Engineer

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan