Application Security Engineer

ReTool

San Francisco (CA)

On-site

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Retool is seeking an Application Security Engineer who combines deep security fundamentals with hands-on engineering. You’ll work in code, spot systemic patterns, and build tooling and solutions that address security at scale, making secure outcomes the default.

You’ll collaborate with product teams to understand where code executes and how data flows, and you’ll help shape AI-enabled security practices as the company shipping fast grows more complex.

Qualifications

  • 5+ years hands-on app security and security engineering experience.
  • Ability to operate independently in a fast-moving environment.
  • Communication that earns trust with engineers, not preaching.
  • Track record shipping security tooling or automation across multiple teams.
  • Genuine engineering depth: read, reason about, and review code.
  • Proficiency in TypeScript and Python.
  • Strong AppSec fundamentals: threat modeling and secure code review.
  • Pragmatic, AI‑oriented approach to development and security tooling.

Responsibilities

  • Identify systemic security gaps in codebase and engineering workflows; drive durable solutions with engineering teams.
  • Build security tooling, automation, and code-level controls to catch issues earlier.
  • Conduct in-depth code reviews and security design reviews for major initiatives.
  • Drive threat modeling and security assessments for new features; translate requirements into practical guidance for developers.
  • Contribute to AI-assisted security approaches as development scales; evaluate where AI adds real value.
  • Triage, track, and drive remediation of vulnerabilities with product engineering teams; participate in pen-testing and bug bounty programs.

Skills

5+ years AppSec
Independent work
Communication skills
Security tooling
Code review
TypeScript
Python
AI tooling

Tools

SAST pipelines
Static analysis
Automated security testing

Job description

WHY WE’R LOOKING FOR YOU

Retool handles our customers’ most sensitive data and provides a platform where they write and execute arbitrary code. The security surface that comes with that is large, nuanced, and genuinely interesting. As the platform grows and our customers’ trust in it deepens, the scope and ambition of our security program have grown with it.

We’re looking for an Application Security Engineer who combines deep security fundamentals with real engineering execution. This is not a role for someone who audits from a distance or advises without getting their hands dirty. You’ll be in the code, spotting systemic patterns, and building the tooling and solutions that address them at scale. You’ll recognize when a one‑off fix isn’t enough, synthesize what you’re seeing in the codebase, and work with engineering teams to make secure outcomes the default rather than the exception.

You’ll need to understand the product deeply to secure it well: what customers build on Retool, where code executes, and how data flows. The security problems worth solving here live at the intersection of platform capability and customer trust, and your first team is the business, not just security.

We’re also actively thinking about what AI‑accelerated development means for application security, from how to use AI to enhance and scale our own security work to managing the risk that comes with developers shipping more code, faster, with different review patterns than ever before. We’re already running experiments in this space, including using AI to find and fix vulnerabilities at scale, automating dependency management, and rethinking what security teams can actually accomplish with the right tooling and ambition. If you want to work out what AI genuinely changes about security engineering practice – in real conditions, not in theory – this role is for you.

IN THIS ROLE, YOU WILL:
  • Identify systemic security gaps in our codebase and engineering workflows, and work with engineering teams to design and ship durable solutions; you’ll drive solutions, not just surface problems
  • Build security tooling, automation, and code‑level controls that address classes of vulnerabilities, including custom linters, static analysis rules, and automated checks, shifting the cost of catching issues left rather than handling them one at a time or after they’ve reached production
  • Conduct in‑depth code reviews and security design reviews for significant product initiatives, with the technical depth to engage meaningfully with architectural tradeoffs rather than just flag issues for others to resolve
  • Drive threat modeling and security assessments for new features, and translate security requirements into practical engineering guidance that developers can actually act on
  • Contribute to the team’s evolving approach to security as AI‑assisted development scales internally, including how faster and higher‑volume code production changes how we find, prioritise, and fix risks
  • Triage, track, and drive remediation of vulnerabilities with product engineering teams, and contribute to our penetration testing and bug bounty programs
THE SKILLSET YOU’LL BRING:
  • 5+ years of hands‑on experience in application security and security engineering: you’ve built things, not only assessed them, and your background is not mainly consulting, audit, or compliance work
  • The ability to operate independently with good judgment in a fast‑moving environment: you prioritise well by understanding the needs of the business and our shared objectives, make calls with incomplete information, and know when to move fast versus when to slow down and get it right, or ask for help
  • Communication that earns trust: you can make security legible to engineers without being preachy, and you measure your impact by how well you’ve supported the business, not by how many issues you catalogued
  • A track record of shipping security tooling or automation that improved things for more than one team
  • Genuine engineering depth: you can read, reason about, and review code at the level needed to find real bugs and understand their root causes, not just pattern‑match to a checklist
  • Comfort working in TypeScript and Python: Retool’s platform is built in TypeScript and our security tooling leans on Python, you’ll need to be productive in both and not just conversant
  • Strong AppSec fundamentals: threat modeling, secure code review, a working understanding of common vulnerability classes and, importantly, how to address them durably rather than symptomatically
  • A pragmatic, signal‑oriented relationship with AI tooling: you reach for it where it genuinely sharpens your work, you’re skeptical where it doesn’t, and you’re thinking about what developer‑side AI adoption means for how security risk compounds at scale
NICE TO HAVE:
  • Offensive security experience like bug bounty, CTF participation, redteam, or pentesting work
  • Experience building or contributing to SAST pipelines, custom static analysis rules, or automated security testing infrastructure
  • Prior experience at a startup or high‑growth scaleup, where security programs aren’t fully pre‑defined and priorities shift
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer San Francisco, United States
Application Security Engineer San Francisco, United States

Retool, Inc. • San Francisco (CA)

Hybrid
USD 231,900 - 318,250
Medical insurance
Dental insurance
Vision insurance
+1
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Senior AppSec Engineer: Build Security at Scale
Senior AppSec Engineer: Build Security at Scale

ReTool • San Francisco (CA)

On-site
USD 150,000 - 230,000
Application Security Engineer
Application Security Engineer

Awardco, Inc. • Lindon (UT)

On-site
USD 110,000 - 140,000
Software Engineer, Enterprise Expansion San Francisco, United States
Software Engineer, Enterprise Expansion San Francisco, United States

Retool, Inc. • San Francisco (CA)

Hybrid
USD 164,000 - 306,000
Medical, dental, vision
401(k) plan
Hybrid work location
Software Engineer, Apps Builder Experience San Francisco, United States
Software Engineer, Apps Builder Experience San Francisco, United States

Retool, Inc. • San Francisco (CA)

Hybrid
USD 163,000 - 306,000
Generous benefits including medical, dental, and vision
401(k) plan
Hybrid work location
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Software Engineer San Francisco, United States
Software Engineer San Francisco, United States

Retool, Inc. • San Francisco (CA)

On-site
USD 163,800 - 306,000
Medical insurance
Dental insurance
Vision insurance
+2
IT Engineer
IT Engineer

Retool, Inc. • San Francisco (CA)

Hybrid
USD 150,000 - 200,000
Hybrid work location
Medical, dental, vision, 401(k)
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent, Inc. • Tysons (VA)

Hybrid
USD 120,000 - 160,000