Application Security Engineer

Jobtailor

San Francisco (CA)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced security engineer to guide developers in secure coding and threat modeling. You will collaborate with software teams to embed security into the lifecycle, perform code reviews, and manage vulnerability remediation using SAST/DAST/SCA and AI tooling.

The role requires deep knowledge of C++ and Python, familiarity with CI/CD pipelines, and experience communicating risk to technical and non-technical stakeholders. Strong training and mentoring skills are valued.

Qualifications

  • 5+ years of total experience with at least 1 year in Application Security or security tasks in a development role.

Responsibilities

  • Partner with the engineering team to provide hands-on technical guidance through the vulnerability remediation lifecycle.
  • Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external pentesting.
  • Support engineering on vulnerability management, including risk assessment and translating security requirements into technical specs.
  • Build security awareness through training on secure coding practices and security standards.

Skills

Security Communication
Coaching
Risk Reasoning
Stakeholder Engagement
Training

Education

BS in Computer Science
Relevant Certifications

Tools

C++
Python
SAST
DAST
SCA
Github Copilot
CI/CD Pipelines
In-House AI Tooling

Job description

  • Partner with the engineering team to provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle. Perform secure code reviews, validate false positive determinations, coach developers on effective remediation strategies, threat model our products and carry out essential parts of a secure SDLC.
  • Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage external penetration testing.
  • Support engineering team on vulnerability management, including risk assessment, remediation, improving identification of vulnerabilities and translate security and privacy requirements into technical requirements.
  • Build security awareness through training on secure coding practices, security standards and latest security threats.
Requirements
  • Security Communication – Ability to reason about risk in complex environments and communicate that risk to technical and non-technical audiences. Experience leading training, speaking internally/externally about security projects valued.
  • Programming Skills – Experience writing and maintaining code in at least one modern programming language and with at least one scripting language (Heartflow uses C++/Python). Comfortable with testing frameworks and CI/CD pipelines.
  • AI Development Tools – Experience using AI code tools such as Claude Code and Github Copilot for development and security testing.
  • Education & Experience – BS in Computer Science (or related degree) or relevant certifications and equivalent experience. 5+ years of total experience with at least 1 year working in Application Security or performing security tasks in a development role.
  • Securing SDLC – Have contributed to secure SDLC activities, including threat modeling, code review, security testing and vulnerability management.
  • Knowledge of Modern AI Security Threats – Experience working with or ability to discuss current AI threats for both machine learning and generative AI.
Core Competencies

Emphasize expertise in secure software development lifecycle (SDLC) practices, including secure code reviews, vulnerability management, and risk assessment. Highlight experience in programming, particularly in C++ and Python, along with familiarity with AI development tools and modern security threats.

Highest-signal resume keywords
  • Secure Software Development Lifecycle (SDLC)
  • Vulnerability Management
  • Risk Assessment
  • Secure Code Reviews
  • AI Development Tools
ATS Optimization Keywords
Hard Skills
  • C++
  • Python
  • SAST
  • DAST
  • SCA
Soft Skills
  • Security Communication
  • Training
  • Coaching
  • Risk Reasoning
  • Stakeholder Engagement
Certifications & Qualifications
  • BS in Computer Science
  • Relevant Certifications
Industry Keywords
  • Application Security
  • Vulnerability Remediation
  • Threat Modeling
  • Security Standards
  • AI Security Threats
Tools & Technologies
  • AI Code Tools
  • Github Copilot
  • CI/CD Pipelines
  • Testing Frameworks
  • In-House AI Tooling
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • Chicago (IL)

On-site
USD 150,000 - 200,000
Senior Application Security Architect
Senior Application Security Architect

Jobtailor • Cary (NC)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • North Carolina

On-site
USD 110,000 - 170,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • United States

On-site
USD 140,000 - 190,000
Staff Software Engineer, Product Security
Staff Software Engineer, Product Security

Jobtailor • California (MO)

On-site
USD 180,000 - 260,000
Software Engineer
Software Engineer

Jobtailor • New Jersey

On-site
USD 110,000 - 170,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Senior Product Security Engineer
Senior Product Security Engineer

Jobtailor • California (MO)

On-site
USD 140,000 - 180,000
Senior Security Engineer – Penetration Tester
Senior Security Engineer – Penetration Tester

Jobtailor • North Carolina

On-site
USD 120,000 - 190,000
Cybersecurity Engineer IV – Application Security
Cybersecurity Engineer IV – Application Security

Jobtailor • Illinois

On-site
USD 140,000 - 180,000