Engineering Manager, Application Security

Qualia

Austin (TX)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
Customized workstations
Unlimited learning
Hot meals & stocked kitchen

Job summary

Qualia in Austin, TX is seeking an Engineering Manager to lead the Application Security team. This builder’s role focuses on redesigning how AppSec operates with AI-augmented workflows across a JavaScript/NodeJS and Kubernetes stack.

You’ll scale security output, build automated pen-testing pipelines, drive AI-driven triage of findings, and partner with Platform, Infra, and product engineering to embed security earlier in development.

Qualifications

  • 5+ years in security or full-stack engineering on production systems
  • 2+ years managing security or platform engineering teams
  • Track record shipping automation with AI/LLM in security or engineering workflows

Responsibilities

  • Lead and grow the AppSec team, setting goals and delivering on the security roadmap
  • Build automated pen-testing pipelines with AI-assisted workflows
  • Scale triage to handle increased findings and noise
  • Review RFCs and proposals with engineering leaders to ship securely by default
  • Lead incident response from the application security side and drive recovery

Skills

Security leadership
AppSec
Automation
AI/ML in security
Threat modeling
Incident response
Cross-functional collaboration
Communication

Tools

Kubernetes
AWS
NodeJS
Typescript
MongoDB

Job description

  • We are hiring an entrepreneurial Engineering Manager to lead Qualia’s Application Security team
  • This is a builder’s role
  • You won’t just run a team - you’ll redesign how a modern AppSec function operates when AI can do the first pass on nearly everything we used to do by hand
  • The team today owns secure design reviews, vulnerability triage, internal penetration testing, incident response support, and security tooling across a JavaScript/NodeJS and Kubernetes stack
  • Your mandate is to scale that surface area vertically - growing output and coverage per engineer - by making AI-assisted workflows the default
  • That means automated pen testing pipelines, AI-driven triage of findings from SAST/DAST/SCA, agentic review of engineering proposals and design docs, and continuous red-teaming exercises that test both our systems and our assumptions
  • You’ll partner closely with Platform, Infra, and product engineering leaders to embed security earlier in the development lifecycle, and you’ll be the team’s voice when we set the security vision for the next two years - including anomaly detection across production traffic, model-driven threat hunting, and how we defend against (and responsibly use) AI-enabled attackers
  • Securing that platform - the money, the identities, and the documents flowing through it - is what the Application Security team does every day
  • We’re hiring an Engineering Manager to lead this team into its next chapter: one where AI is a force multiplier for every part of our security program
  • Lead and grow the Application Security team - coaching senior AppSec engineers, setting goals, and owning delivery against the security roadmap
  • Build the automated pen-testing program. Stand up pipelines that run continuous, AI-assisted offensive testing against our services, APIs, and web properties - and turn the output into a triaged, actionable queue
  • Scale triage with AI. Design the workflows and tooling that let the team handle 10x the volume of findings (bug bounty, scanner output, customer reports) without 10x the headcount
  • Review engineering proposals. Sit at the front of the design process with engineering leaders across Core, Clear, Shield, Connect, and Atlas - reviewing RFCs and proposals, flagging risk early, and helping teams ship securely by default
  • Run red-teaming exercises. Drive recurring red team engagements - both internal exercises and coordinated vendor work - and close the loop into detection, response, and product hardening
  • Own the AppSec vision. Partner with the leadership team to set multi-quarter strategy across anomaly detection, threat modeling, and AI-augmented defense
  • Fight fires when they happen. Lead incident response from the application security side, and be the person engineering trusts to make the call in the room
  • Mentor and hire. Recruit strong AppSec engineers, mentor the ones you have, and build a team culture where people are pushed and supported in equal measure
  • THE TECH STACK YOU’LL USE:
  • JavaScript / NodeJS / Typescript / Meteor
  • Microservice architecture / Kubernetes Operators
  • AWS
  • MongoDB
  • Modern AppSec tooling: SAST/DAST/SCA and an expanding AI-assisted security automation layer that you’ll help build
Benefits
  • Medical, Dental & Vision: Healthcare plans to keep your mind and body healthy.
  • Competitive salary & equity: Our team builds together and benefits together.
  • Flexible schedules: Our focus is on results so work at your peak hours.
  • Customized workstations: It helps to build the best when your tools are the best.
  • Unlimited learning: Better yourself with in-house and external courses.
  • Hot meals & a stocked kitchen: Daily catered lunches so you’re always well fed.
  • 5+ years as a security or full-stack engineer working on production systems, with 2+ years managing a security or platform engineering team
  • Track record of shipping automation that changed how a team worked - ideally including meaningful use of LLMs, agents, or ML in a security or engineering workflow
  • Keen product sense and a bias toward measurable impact. You care whether the risk actually went down, not whether a ticket got closed
  • Strong written communication. You can write the design doc, the post-mortem, and the board-ready summary - and you can tell a product engineer why their proposal needs to change without shutting down the conversation
  • Comfort operating across the full security lifecycle: prevention, detection, response, and recovery
  • Hands-on depth in application security: threat modeling, code review, and at least one offensive-security discipline (pen testing, red team)
  • Experience in fintech, real estate tech, or another regulated, high-liability domain preferred
  • Published research, CVEs, or conference talks in AppSec, offensive security, or AI security
  • Background designing or operating anomaly-detection systems on production traffic, auth logs, or financial transactions
  • Familiarity with the evolving landscape of AI-enabled offense (prompt injection, model abuse, agent exploitation) and defense
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent, Inc. • Virginia (MN)

On-site
USD 120,000 - 160,000
Hybrid work model
Competitive benefits
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Virginia (MN)

On-site
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Simile • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Namely • United States

On-site
USD 120,000 - 160,000
Bonus
Engineering Manager, Information Security
Engineering Manager, Information Security

Qualia • Austin (TX)

On-site
USD 180,000 - 230,000
Health plans
401k
Commuter benefits
+6
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Security Engineer - Application Security (Senior)
Security Engineer - Application Security (Senior)

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
AI Security Full Stack Engineering Manager
AI Security Full Stack Engineering Manager

Lincoln Motor Company • United States

Remote
USD 180,000 - 230,000