Application Security Engineer — Secure AI Apps & APIs

Hark

San Jose (CA)

On-site

USD 150,000 - 300,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Hark, an AI company building multimodal models and next-generation hardware, is hiring a Member of Technical Staff (Application Security Engineer) to own the security of the software Hark ships. You'll review design and code, find and fix vulnerabilities in our backend services, mobile apps, and third-party integrations, and build guardrails that let engineers move fast without shipping bugs.

Our agents act on behalf of users across their apps and data, so you'll also be defining how to secure

Qualifications

  • 4-8 years of hands-on application or product security engineering experience.
  • Strong software engineering skills; you can read, write, and ship production code (Go strongly preferred; Python, TypeScript, Swift, or Kotlin also valuable).
  • Deep understanding of web and API vulnerability classes (OWASP Top 10, SSRF, IDOR/BOLA, authz flaws, injection) and how to fix them at the root.
  • Hands-on experience with OAuth 2.0 / OIDC, session management, and securing multi-tenant systems.
  • Experience running secure code review and threat modeling in a fast-moving engineering org.
  • Experience turning scanner and runtime findings into fixes using tools like Wiz Code, Wiz Cloud, and Datadog SIEM (or equivalent SAST/SCA, CNAPP, and SIEM tools).
  • Real curiosity about LLM and agent security; this is new territory and we want someone excited to figure it out.

Responsibilities

  • Threat-model new features and services, with a focus on agent/LLM attack surfaces (prompt injection, tool misuse, data exfiltration, cross-tenant access).
  • Review code and designs for Hark's backend services (primarily Go), APIs, and mobile apps; fix vulnerabilities directly when it's faster than filing a ticket.
  • Secure authentication, authorization, and session handling across our consumer product, including OAuth integrations with third-party platforms.
  • Build and tune SAST, dependency, and secrets scanning in CI so findings are high-signal and developers actually act on them.
  • Triage and remediate findings from pentests and our vulnerability disclosure program.
  • Partner with engineering to embed security into the development lifecycle through paved roads, secure defaults, and reusable libraries.

Skills

Go
Python
TypeScript
Swift
Kotlin
OAuth 2.0 / OIDC
Web security
Threat modeling

Tools

Wiz Code
Wiz Cloud
Datadog SIEM

Job description

Hark, an AI company building multimodal models and next-generation hardware, is hiring a Member of Technical Staff (Application Security Engineer) to own the security of the software Hark ships. You'll review design and code, find and fix vulnerabilities in our backend services, mobile apps, and third-party integrations, and build guardrails that let engineers move fast without shipping bugs.

Our agents act on behalf of users across their apps and data, so you'll also be defining how to secure

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Hark • San Jose (CA)

On-site
USD 150,000 - 300,000
Staff AI Application Security Engineer — Secure by Design
Staff AI Application Security Engineer — Secure by Design

Writer • California (MO)

Hybrid
USD 180,000 - 240,000
Generous PTO
Medical, dental, vision coverage
Parental leave
Information Security Engineer
Information Security Engineer

Hark • San Jose (CA)

On-site
USD 150,000 - 300,000
Security Engineer — Secure AI-Powered Apps & CI/CD
Security Engineer — Secure AI-Powered Apps & CI/CD

Air Apps • San Francisco (CA)

On-site
USD 110,000 - 193,000
Annual Bonus
Medical Insurance (vision & dental)
Disability insurance - short and long‑
+6
AI Security Engineer — Secure AI-Driven Apps
AI Security Engineer — Secure AI-Driven Apps

Fortinet • Sunnyvale (CA)

On-site
USD 160,000 - 220,000
Medical insurance
Dental insurance
401(k)
+3
Staff Security Engineer: AI App Security & Secure Coding
Staff Security Engineer: AI App Security & Secure Coding

Showcify, Inc. • United States

Hybrid
USD 170,000 - 230,000
Generous PTO
Health coverage
Parental leave
+3
Senior AI Security Engineer — Secure AI Platforms
Senior AI Security Engineer — Secure AI Platforms

EngineersOfAI • United States

On-site
USD 120,000 - 160,000
Staff Application Security Engineer – AI/ML
Staff Application Security Engineer – AI/ML

WRITER • San Francisco (CA)

Hybrid
USD 183,000 - 240,000
Generous PTO and holidays
Medical, dental, vision coverage
Parental leave (16 weeks)
+3
Senior Software Engineer, AI Platform — Security & Cloud
Senior Software Engineer, AI Platform — Security & Cloud

hackerone • Boston (MA)

Hybrid
USD 182,000 - 222,000
Health insurance
Equity options
Retirement plan
+4
Senior Product Security Engineer - Build Secure AI
Senior Product Security Engineer - Build Secure AI

Harvey • United States

Remote
USD 140,000 - 200,000