Application Security Engineer

Zof AI

San Francisco, Northern (CA, KY)

Hybrid

USD 150,000 - 210,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Zof AI in San Francisco is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer code. The role focuses on isolating agent workloads, secrets handling, supply chain security, and enterprise controls that buyers audit before trusting a repository.

Responsibilities include hardening sandbox and tenant isolation, designing access controls, securing the software supply chain, and enabling SOC 2 compliance.

Qualifications

  • Experience securing production software systems or cloud infrastructure.
  • Strong software engineering foundation and comfort shipping code.
  • Working knowledge of application security and common vulnerability classes.
  • Experience with cloud security, identity, and access control.
  • Familiarity with SOC 2 controls and audit readiness.
  • Clear written and verbal communication.

Responsibilities

  • Own the security posture of a platform that reads, executes, and modifies customer source code.
  • Harden the sandbox, tenant, and workload isolation boundaries agents run inside.
  • Design secrets management and least privilege access across the platform.
  • Secure the software supply chain from dependencies through build and deploy.
  • Build the technical controls behind SOC 2 and enterprise security requirements.
  • Teach agent fleets to find, prove, and remediate real vulnerabilities in customer code.
  • Run threat modeling, design reviews, and incident response as part of regular practice.
  • Partner with engineering and sales to clear enterprise security reviews and questionnaires.

Skills

Threat modeling
Application security
Cloud security
Secure coding
Security reviews
Communication

Education

Bachelor's in CS/SE
Security certs (CISSP, etc.)

Tools

Static analysis
Fuzzing tools

Job description

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and the enterprise controls that buyers audit before they trust us with a repository. If you have worked as an Application Security Engineer, Product Security Engineer, Cloud Security Engineer, or Infrastructure Security Engineer, this is that discipline at Zof AI. The ideal candidate thinks in threat models, ships controls instead of policy documents, and treats customer code as the most sensitive asset we hold.

Engineering · Mid to Senior · Full-time · On-site · San Francisco, CA

Responsibilities
  • Own the security posture of a platform that reads, executes, and modifies customer source code.
  • Harden the sandbox, tenant, and workload isolation boundaries agents run inside.
  • Design secrets management, credential handling, and least privilege access across the platform.
  • Secure the software supply chain from dependencies through build and deploy.
  • Build the technical controls behind SOC 2 and enterprise security requirements.
  • Teach our agent fleets to find, prove, and remediate real vulnerabilities in customer code.
  • Run threat modeling, design reviews, and incident response as a regular practice.
  • Partner with engineering and sales to clear enterprise security reviews and questionnaires.
Requirements
  • Experience securing production software systems or cloud infrastructure.
  • Strong software engineering foundation and comfort shipping code, not just reviewing it.
  • Working knowledge of application security and common vulnerability classes.
  • Experience with cloud security, identity, and access control.
  • Familiarity with compliance frameworks such as SOC 2.
  • Clear written and verbal communication.
  • Comfort operating in a fast-moving environment.
  • High ownership of security outcomes, not just findings.
Nice to have
  • Experience with sandboxing, container isolation, or multi-tenant architecture.
  • Experience with LLM or agent security, including prompt injection and tool use risk.
  • Experience with static analysis, fuzzing, or automated vulnerability detection.
  • Experience leading enterprise security reviews or SOC 2 audit readiness.

Hands-on experience working with AI agents and threat modeling what they are allowed to do is required

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 230,000
Platform Security Engineer: Threat Modeling & Isolation
Platform Security Engineer: Threat Modeling & Isolation

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Forward Deployed Software Engineer
Forward Deployed Software Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Application Security Engineer – Software Composition Analysis (SCA)
Application Security Engineer – Software Composition Analysis (SCA)

Zelis • Plano (TX)

On-site
USD 120,000 - 180,000
Full Stack Software Engineer
Full Stack Software Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 110,000 - 165,000
Applied AI Engineer
Applied AI Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Backend Software Engineer
Backend Software Engineer

Zof AI • San Francisco (CA), Northern (KY)

Hybrid
USD 120,000 - 190,000