Lead Application Security Engineer, Code to Cloud

Beacon Roofing Supply, Inc

Vancouver (WA)

On-site

USD 101,000 - 172,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

QXO is building a modern cybersecurity function from the ground up, automation-first, and you will own the engineering behind Code to Cloud: continuous security coverage across the software delivery lifecycle, from source code through pipeline execution to cloud runtime.

You will drive policy-based blocking in PRs and CI/CD, shape security standards, and mentor engineers across three engineering organizations.

Qualifications

  • 8+ years in application security or DevSecOps with hands-on work.
  • Experience owning an enterprise-scale security program across multiple teams.
  • Written policy and API-based security controls; not just dashboards.

Responsibilities

  • Own scanning and posture platform end-to-end across SAST/SCA/IAAC and cloud runtime.
  • Build policy-based blocking in PRs and CI/CD with a risk-based gating.
  • Define security standards, risk-acceptance workflows, and threat modeling templates.
  • Participate in architecture reviews on authorization and service identity.
  • Coach security champions, mentor engineers, and mentor third-party testing partners.
  • Oversee security testing of running apps and respond to critical vulnerabilities.

Skills

Security program ownership
Cloud-native security
Policy-as-code
Threat modeling
Architecture review
DAST/API security testing
Python/Go/TypeScript
AI-assisted triage

Education

Bachelor’s in CS/InfoSec

Tools

Wiz
Snyk
Prisma Cloud
Orca

Job description

As a Lead Application Security Engineer, Code to Cloud at QXO, you’ll be the recognized subject matter expert for application security across the company and own the engineering behind Code to Cloud: continuous security coverage across QXO’s software delivery lifecycle, from source code through pipeline execution to cloud runtime.

QXO is building a modern cybersecurity function from the ground up, automation-first. This is a large, enterprise-wide program spanning three engineering organizations, and you will run your part of it with limited oversight, defining the standards QXO builds against rather than applying someone else’s. Attackers operate at machine speed, and human-speed review cannot meet that, so we automate first.

QXO is a leading distributor and installer of building products serving an $800 billion market. The company’s mission is to modernize the building products industry through advanced technology and a best-in-class customer experience. QXO is North America’s largest distributor and installer of insulation, the second-largest distributor of roofing products, the second-largest publicly traded distributor of lumber and building materials, and the largest distributor of waterproofing products. The company is targeting $50 billion in annual revenue within the decade through accretive acquisitions and organic growth. For more information, visit QXO.com.

What you’ll do
  • Own the scanning and posture platform end to end across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, at a false-positive rate engineers trust. Build the automation that routes, deduplicates, and prioritizes findings, with owner resolution, SLA tracking, and closure verification.
  • Build and run policy-based blocking controls in pull requests and CI/CD pipelines, as policy-as-code applied centrally and scoped to repository tiering, so coverage inherits to future repositories. Turn a gate on only when the baseline is triaged and false positives are under bar, and never block a team without a path forward.
  • Author the application security standards, secure design patterns, and remediation SLAs QXO builds against, own the exception and risk-acceptance workflow, and report on risk reduced rather than finding counts. Make threat modeling repeatable through templates and AI-assisted triage, producing testable requirements.
  • Sit in architecture and design reviews with principal engineers and reach a decision in the room: where a gateway-validated token stops being sufficient and service identity needs its own mechanism, how object-level authorization survives a list endpoint, and why a service must never take an authorization attribute from its caller. Review third-party integrations before production.
  • Set the technical bar for the practice: coach, review, and direct the security work of the champions network and third-party testing partners, and mentor engineers added to the team. Be the person engineering calls, explaining what a finding means and what it does not, so a blocked developer gets an answer the same day.
  • Own security testing of the running application, not just its source, and work with developers to remediate what it finds, verifying on retest. Lead the response when a critical vulnerability or exploit drops.
  • Lead the security integration of acquired engineering environments, bringing their repositories, pipelines, and cloud accounts under coverage without stalling delivery.
What you’ll bring
  • 8+ years in application security, product security, DevSecOps, or security engineering, most of it hands-on rather than advisory.
  • Hands‑on experience owning an enterprise‑scale security program across multiple teams and stakeholder groups with limited oversight, including setting standards others follow and reviewing the work of other engineers.
  • Depth in a cloud‑native application protection or application security posture platform such as Wiz, Snyk, Prisma Cloud, or Orca. You have written policy and built on its API, not just read dashboards.
  • Pipeline enforcement you have actually shipped: policy‑based blocking in pull requests and CI/CD, security policy‑as‑code, and the harder part, moving a control from advisory to blocking without an engineering revolt.
  • Threat modeling you have run, not just studied. STRIDE or an equivalent applied to real systems, extended with MITRE ATLAS and the LLM risk taxonomies where classical categories fall short on AI‑enabled systems.
  • Architecture‑level security judgment. You can hold your own with a principal engineer on authorization design in a distributed system: trust boundaries, token validation, service‑to‑service identity, and object‑level access control.
  • Approachable, responsive, and constructive under pressure. You can tell a team their launch has a problem without becoming the reason they route around security.
  • An automation‑first, AI‑forward way of working, and a defensible view on securing AI itself: validating AI‑generated code, and agentic risk including prompt injection, tool permissions, and the MCP supply chain.
  • Dynamic testing of running applications and APIs through DAST tooling, API security testing, or hands‑on offensive work, and cloud security depth in a major public cloud, Google Cloud a plus.
  • Coding ability in Python, Go, or TypeScript, and writing that is tight, evidence‑backed, and defensible when challenged.
Education & Certifications
  • Bachelor’s in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred. Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect. CSSLP, GWAPT, OSWE, or OSCP a plus.
What you’ll earn
  • Base pay range: $101,300 - $172,000
  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • PTO, company holidays, and parental leave
  • Paid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.
  • Paid training and certifications
  • Legal assistance and identity protection
  • Pet insurance
  • Employee assistance program (EAP)

QXO is an Equal Opportunity Employer. We value diversity and do not discriminate on the basis of race, color, religion, gender or sexual orientation, national origin, age, disability, or any other protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Application Security Engineer, Code to Cloud
Lead Application Security Engineer, Code to Cloud

QXO • Vancouver (WA)

On-site
USD 101,000 - 172,000
Medical, dental, and vision insurance
PTO and holidays
401(k) with employer match
Cybersecurity Lead Associate — Third-Party Risk Management
Cybersecurity Lead Associate — Third-Party Risk Management

Beacon Roofing Supply, Inc • Charlotte (NC)

On-site
USD 101,000 - 172,000
Annual bonus
401(k) with employer match
Medical, dental, and vision insurance
+2
Lead Associate Engineer, Identity and Access Management
Lead Associate Engineer, Identity and Access Management

Beacon Roofing Supply, Inc • Charlotte (NC)

On-site
USD 101,000 - 172,000
Annual performance bonus
401(k) with employer match
Medical, dental, and vision insurance
+2
Staff Software Engineer, Data
Staff Software Engineer, Data

Beacon Roofing Supply, Inc • Seattle (WA)

On-site
USD 175,000 - 400,000
Base pay range: $175,000 - $400,000
Annual performance bonus
Medical, dental, and vision insurance
Staff Software Engineer, BackEnd
Staff Software Engineer, BackEnd

Beacon Roofing Supply, Inc • Seattle (WA)

On-site
USD 150,000 - 275,000
Annual performance bonus
Long-term incentive (equity)
401(k) with employer match
+5
Senior Software Engineer
Senior Software Engineer

QXO • Seattle (WA)

On-site
USD 170,000 - 235,000
Medical, dental, and vision insurance
401(k) with employer match
PTO and holidays
+1
Senior Software Engineer, Mobile
Senior Software Engineer, Mobile

QXO • Seattle (WA)

On-site
USD 158,000 - 214,000
Annual bonus
Stock options
401(k) with employer match
+5
Lead Associate Engineer, Identity and Access Management
Lead Associate Engineer, Identity and Access Management

QXO • Charlotte (NC)

On-site
USD 101,000 - 172,000
401(k) with employer match
Medical, dental, and vision insurance
PTO and holidays
+3
Staff Software Engineer, Full Stack
Staff Software Engineer, Full Stack

QXO • Seattle (WA)

On-site
USD 150,000 - 275,000
Annual performance bonus
401(k) with employer match
Medical, dental, and vision insurance
+2
Staff Software Engineer, Full Stack
Staff Software Engineer, Full Stack

QXO • Herndon (VA)

On-site
USD 160,000 - 288,000
Annual performance bonus
401(k) with employer match
Medical, dental, and vision insurance
+2