Engineering Manager, Application Security

Qualia

Austin (TX)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
Customized workstations
Unlimited learning
Hot meals & stocked kitchen

Job summary

Qualia in Austin, TX is seeking an Engineering Manager to lead the Application Security team. This builder’s role focuses on redesigning how AppSec operates with AI-augmented workflows across a JavaScript/NodeJS and Kubernetes stack.

You’ll scale security output, build automated pen-testing pipelines, drive AI-driven triage of findings, and partner with Platform, Infra, and product engineering to embed security earlier in development.

Qualifications

  • 5+ years in security or full-stack engineering on production systems
  • 2+ years managing security or platform engineering teams
  • Track record shipping automation with AI/LLM in security or engineering workflows

Responsibilities

  • Lead and grow the AppSec team, setting goals and delivering on the security roadmap
  • Build automated pen-testing pipelines with AI-assisted workflows
  • Scale triage to handle increased findings and noise
  • Review RFCs and proposals with engineering leaders to ship securely by default
  • Lead incident response from the application security side and drive recovery

Skills

Security leadership
AppSec
Automation
AI/ML in security
Threat modeling
Incident response
Cross-functional collaboration
Communication

Tools

Kubernetes
AWS
NodeJS
Typescript
MongoDB

Job description

  • We are hiring an entrepreneurial Engineering Manager to lead Qualia’s Application Security team
  • This is a builder’s role
  • You won’t just run a team - you’ll redesign how a modern AppSec function operates when AI can do the first pass on nearly everything we used to do by hand
  • The team today owns secure design reviews, vulnerability triage, internal penetration testing, incident response support, and security tooling across a JavaScript/NodeJS and Kubernetes stack
  • Your mandate is to scale that surface area vertically - growing output and coverage per engineer - by making AI-assisted workflows the default
  • That means automated pen testing pipelines, AI-driven triage of findings from SAST/DAST/SCA, agentic review of engineering proposals and design docs, and continuous red-teaming exercises that test both our systems and our assumptions
  • You’ll partner closely with Platform, Infra, and product engineering leaders to embed security earlier in the development lifecycle, and you’ll be the team’s voice when we set the security vision for the next two years - including anomaly detection across production traffic, model-driven threat hunting, and how we defend against (and responsibly use) AI-enabled attackers
  • Securing that platform - the money, the identities, and the documents flowing through it - is what the Application Security team does every day
  • We’re hiring an Engineering Manager to lead this team into its next chapter: one where AI is a force multiplier for every part of our security program
  • Lead and grow the Application Security team - coaching senior AppSec engineers, setting goals, and owning delivery against the security roadmap
  • Build the automated pen-testing program. Stand up pipelines that run continuous, AI-assisted offensive testing against our services, APIs, and web properties - and turn the output into a triaged, actionable queue
  • Scale triage with AI. Design the workflows and tooling that let the team handle 10x the volume of findings (bug bounty, scanner output, customer reports) without 10x the headcount
  • Review engineering proposals. Sit at the front of the design process with engineering leaders across Core, Clear, Shield, Connect, and Atlas - reviewing RFCs and proposals, flagging risk early, and helping teams ship securely by default
  • Run red-teaming exercises. Drive recurring red team engagements - both internal exercises and coordinated vendor work - and close the loop into detection, response, and product hardening
  • Own the AppSec vision. Partner with the leadership team to set multi-quarter strategy across anomaly detection, threat modeling, and AI-augmented defense
  • Fight fires when they happen. Lead incident response from the application security side, and be the person engineering trusts to make the call in the room
  • Mentor and hire. Recruit strong AppSec engineers, mentor the ones you have, and build a team culture where people are pushed and supported in equal measure
  • THE TECH STACK YOU’LL USE:
  • JavaScript / NodeJS / Typescript / Meteor
  • Microservice architecture / Kubernetes Operators
  • AWS
  • MongoDB
  • Modern AppSec tooling: SAST/DAST/SCA and an expanding AI-assisted security automation layer that you’ll help build
Benefits
  • Medical, Dental & Vision: Healthcare plans to keep your mind and body healthy.
  • Competitive salary & equity: Our team builds together and benefits together.
  • Flexible schedules: Our focus is on results so work at your peak hours.
  • Customized workstations: It helps to build the best when your tools are the best.
  • Unlimited learning: Better yourself with in-house and external courses.
  • Hot meals & a stocked kitchen: Daily catered lunches so you’re always well fed.
  • 5+ years as a security or full-stack engineer working on production systems, with 2+ years managing a security or platform engineering team
  • Track record of shipping automation that changed how a team worked - ideally including meaningful use of LLMs, agents, or ML in a security or engineering workflow
  • Keen product sense and a bias toward measurable impact. You care whether the risk actually went down, not whether a ticket got closed
  • Strong written communication. You can write the design doc, the post-mortem, and the board-ready summary - and you can tell a product engineer why their proposal needs to change without shutting down the conversation
  • Comfort operating across the full security lifecycle: prevention, detection, response, and recovery
  • Hands-on depth in application security: threat modeling, code review, and at least one offensive-security discipline (pen testing, red team)
  • Experience in fintech, real estate tech, or another regulated, high-liability domain preferred
  • Published research, CVEs, or conference talks in AppSec, offensive security, or AI security
  • Background designing or operating anomaly-detection systems on production traffic, auth logs, or financial transactions
  • Familiarity with the evolving landscape of AI-enabled offense (prompt injection, model abuse, agent exploitation) and defense
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Qualia • United States

Hybrid
USD 180,000 - 210,000
401k program
Comprehensive health plans
Flexible time-off policy
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent, Inc. • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Doist • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Namely • United States

Hybrid
USD 120,000 - 160,000
Bonus
Security Engineer
Security Engineer

Stack AI, Inc. • San Francisco (CA), New York (NY)

Hybrid
USD 120,000 - 160,000
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2
Engineering Manager
Engineering Manager

Safe Security • Town of Delhi (NY)

On-site
USD 180,000 - 240,000
Equity
Unlimited Leave
Comprehensive Benefits
+1