Application Security Engineer

Hark

San Jose (CA)

On-site

USD 150,000 - 300,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Hark, an AI company building multimodal models and next-generation hardware, is hiring a Member of Technical Staff (Application Security Engineer) to own the security of the software Hark ships. You'll review design and code, find and fix vulnerabilities in our backend services, mobile apps, and third-party integrations, and build guardrails that let engineers move fast without shipping bugs.

Our agents act on behalf of users across their apps and data, so you'll also be defining how to secure

Qualifications

  • 4-8 years of hands-on application or product security engineering experience.
  • Strong software engineering skills; you can read, write, and ship production code (Go strongly preferred; Python, TypeScript, Swift, or Kotlin also valuable).
  • Deep understanding of web and API vulnerability classes (OWASP Top 10, SSRF, IDOR/BOLA, authz flaws, injection) and how to fix them at the root.
  • Hands-on experience with OAuth 2.0 / OIDC, session management, and securing multi-tenant systems.
  • Experience running secure code review and threat modeling in a fast-moving engineering org.
  • Experience turning scanner and runtime findings into fixes using tools like Wiz Code, Wiz Cloud, and Datadog SIEM (or equivalent SAST/SCA, CNAPP, and SIEM tools).
  • Real curiosity about LLM and agent security; this is new territory and we want someone excited to figure it out.

Responsibilities

  • Threat-model new features and services, with a focus on agent/LLM attack surfaces (prompt injection, tool misuse, data exfiltration, cross-tenant access).
  • Review code and designs for Hark's backend services (primarily Go), APIs, and mobile apps; fix vulnerabilities directly when it's faster than filing a ticket.
  • Secure authentication, authorization, and session handling across our consumer product, including OAuth integrations with third-party platforms.
  • Build and tune SAST, dependency, and secrets scanning in CI so findings are high-signal and developers actually act on them.
  • Triage and remediate findings from pentests and our vulnerability disclosure program.
  • Partner with engineering to embed security into the development lifecycle through paved roads, secure defaults, and reusable libraries.

Skills

Go
Python
TypeScript
Swift
Kotlin
OAuth 2.0 / OIDC
Web security
Threat modeling

Tools

Wiz Code
Wiz Cloud
Datadog SIEM

Job description

About Hark

Hark is an artificial intelligence company building advanced, personalized intelligence. One that is proactive, multimodal, and capable of interacting with the world through speech, text, vision, and persistent memory.

We're pairing that intelligence with next-generation hardware to create a universal interface between humans and machines. While today's AI largely operates through chat boxes and decade-old devices, Hark is focused on what comes next: agentic systems that interact naturally with people and the real world.

To get there, we're developing multimodal models and next-generation AI hardware together, designed from the ground up as a single, unified interface for a new era of intelligent systems.

About the Role

We're hiring a Member of Technical Staff (Application Security Engineer) to own the security of the software Hark ships. You'll review design and code, find and fix vulnerabilities in our backend services, mobile apps, and third-party integrations, and build the guardrails that let engineers move fast without shipping bugs. Our agents act on behalf of users across their apps and data, so you'll also be defining how to secure LLM and agent systems, a space with very few established playbooks.

This role is hands-on; you'll be reading code, writing fixes, and building tooling, not managing or auditing.

Responsibilities
  • Threat-model new features and services, with a focus on agent/LLM attack surfaces (prompt injection, tool misuse, data exfiltration, cross-tenant access).
  • Review code and designs for Hark's backend services (primarily Go), APIs, and mobile apps; fix vulnerabilities directly when it's faster than filing a ticket.
  • Secure authentication, authorization, and session handling across our consumer product, including OAuth integrations with third-party platforms.
  • Build and tune SAST, dependency, and secrets scanning in CI so findings are high-signal and developers actually act on them.
  • Triage and remediate findings from pentests and our vulnerability disclosure program.
  • Partner with engineering to embed security into the development lifecycle through paved roads, secure defaults, and reusable libraries.
Requirements
  • 4-8 years of hands-on application or product security engineering experience.
  • Strong software engineering skills; you can read, write, and ship production code (Go strongly preferred; Python, TypeScript, Swift, or Kotlin also valuable).
  • Deep understanding of web and API vulnerability classes (OWASP Top 10, SSRF, IDOR/BOLA, authz flaws, injection) and how to fix them at the root.
  • Hands-on experience with OAuth 2.0 / OIDC, session management, and securing multi-tenant systems.
  • Experience running secure code review and threat modeling in a fast-moving engineering org.
  • Experience turning scanner and runtime findings into fixes using tools like Wiz Code, Wiz Cloud, and Datadog SIEM (or equivalent SAST/SCA, CNAPP, and SIEM tools).
  • Real curiosity about LLM and agent security; this is new territory and we want someone excited to figure it out.
Bonus Qualifications
  • Experience at a security-forward product company (Stripe, Coinbase, Discord, Roblox, Netflix) or an offensive security consultancy (Trail of Bits, Bishop Fox, NCC Group).
  • Mobile application security experience (iOS/Android).
  • Prior work on LLM/agent threat modeling, prompt injection defenses, or AI red teaming.
  • Bug bounty, CVE, or open source security contributions.
Compensation

The US base salary range for this full-time position is between $150,000 - $300,000 annually.

The pay offered for this position may vary based on several individual factors, including job-related knowledge, skills, and experience. The total compensation package may also include additional components and benefits depending on the specific role. This information will be shared if an employment offer is extended.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Engineer
Information Security Engineer

Hark • San Jose (CA)

On-site
USD 150,000 - 300,000
Application Security Engineer — Secure AI Apps & APIs
Application Security Engineer — Secure AI Apps & APIs

Hark • San Jose (CA)

On-site
USD 150,000 - 300,000
Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

GoodLeap • United States

On-site
USD 146,000 - 169,000
Bonus eligible
Backend Engineer San Jose
Backend Engineer San Jose

Hark, Inc. • San Jose (CA)

On-site
USD 170,000 - 400,000
Member of Technical Staff, Digital World Engineer San Jose
Member of Technical Staff, Digital World Engineer San Jose

Hark • San Jose (CA), Northern (KY)

Hybrid
USD 170,000 - 400,000
Senior Software Engineer, Applied AI
Senior Software Engineer, Applied AI

hackerone • Boston (MA)

On-site
USD 190,000 - 230,000
Health (medical, vision, dental) insurance
Equity stock options
Retirement plans
+1
Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

United States Digital Space LLC • United States

On-site
USD 140,000 - 190,000
Member of Technical Staff, Hark Desktop San Jose
Member of Technical Staff, Hark Desktop San Jose

Hark • San Jose (CA), Northern (KY)

Hybrid
USD 170,000 - 400,000
Staff Software Engineer, Secure Execution
Staff Software Engineer, Secure Execution

Showcify, Inc. • United States

Remote
USD 231,000 - 346,000
Senior AI Platform Engineer
Senior AI Platform Engineer

hackerone • Washington

On-site
Confidential