Senior Application Security Engineer

Starburst

Boston (MA)

On-site

USD 140,000 - 190,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity packages
Comprehensive benefits

Job summary

Starburst is seeking a Senior Application Security Engineer to own the security program across its self‑managed enterprise platform and SaaS. This hands‑on role embeds secure‑by‑default patterns into how engineers design and ship, and uses automation and AI to scale security across a large product portfolio.

You will drive threat modeling, vulnerability management, and supply‑chain security, while engaging directly with enterprise customers on posture and assurance in high‑trust environments.

Qualifications

  • Bachelor's degree in Computer Science, Engineering, MIS, or equivalent practical experience.
  • 5-7 years of experience in application security, product security, software engineering with a security focus, or a related technical role.
  • Deep command of application and product security fundamentals, with the judgment to distinguish real exploitability from scanner noise.
  • Proven experience embedding security into the SDLC and getting engineering teams to actually adopt it - plus building and scaling processes that raise a program's overall maturity.
  • Demonstrated experience running vulnerability management for shipped software at scale, with strong knowledge of container/image security and JVM dependency and supply chain risk.
  • Offensive security experience and a drive to automate it: red‑teaming, or threat hunting against your own products.
  • Threat modeling experience on distributed systems and data platforms, and a strong bias toward automation, including using AI to scale security work.
  • Experience in enterprise B2B software and working directly with enterprise customers on security, ideally in regulated industries such as financial services.
  • Experience leading and mentoring engineers.

Responsibilities

  • Own and mature the Application Security program, moving it from established practice to measurable, automated, and scaled across a large engineering organization.
  • Shift security left into the SDLC, embedding secure‑by‑default patterns, guardrails, threat modeling, and automated checks into design and development (including for AI‑assisted development) so issues are prevented rather than found late.
  • Build autonomous red‑teaming and threat hunting against our own products, using AI and automation to continuously probe for weaknesses instead of relying on point‑in‑time testing.
  • Own vulnerability management for everything we ship across our self‑managed enterprise platform and SaaS product - container images, third‑party dependencies, and first‑party code - automating detection, triage, and routing, and advancing remediation through reachability/exploitability analysis and attack‑surface reduction.
  • Own application and supply chain security tooling (SAST, SCA, DAST, container scanning), plus third‑party penetration testing and the Vulnerability Disclosure Program.
  • Be the security voice with customers and leadership, working directly with enterprise customers on posture and assurance, and reporting on product security in executive, customer, and audit conversations.

Skills

Application Security
Threat Modeling
Automation
Vulnerability Management
Red Teaming
AI for Security
Mentoring

Education

Bachelor's degree in CS/Engineering/MIS or equivalent

Tools

SAST
SCA
DAST
Container Scanning

Job description

About Starburst

Starburst delivers enterprise intelligence at scale by giving organizations secure, governed access to all their data, wherever it lives. Built for distributed data environments, Starburst helps enterprises power AI and analytics without the cost and complexity of traditional data consolidation. With open standards including Trino and Apache Iceberg, Starburst enables trusted access to complete enterprise context while helping organizations avoid vendor lock‑in. Leading global enterprises trust Starburst to fuel AI, analytics, and enterprise intelligence. Learn more at starburst.ai .

About the role

As our Senior Application Security Engineer, you'll be the technical owner of application and product security at Starburst - one person with outsized impact, backed by automation and AI rather than a large team. This is deep, hands‑on engineering work: you'll build secure‑by‑default patterns into how our engineers design and ship, embed security controls earlier in the development lifecycle, and create the automation that lets you cover a large engineering organization. You'll get to stand up autonomous red‑teaming and threat hunting against our own products, run vulnerability management across both our self‑managed enterprise platform and our SaaS, and advance our software supply chain security. Because our biggest customers are global banks, you'll also be in the room with them, explaining how we secure what we ship - the kind of high‑trust, high‑stakes conversation that makes this work matter.

If you want to make products secure by design rather than chase what's already broken, own a program end to end, and use AI to build defensive tools, this is your opportunity. You'll work closely with Engineering, Product, and the field.

As a Senior Application Security Engineer at Starburst you will:
  • Own and mature the Application Security program , moving it from established practice to measurable, automated, and scaled across a large engineering organization.
  • Shift security left into the SDLC , embedding secure‑by‑default patterns, guardrails, threat modeling, and automated checks into design and development (including for AI‑assisted development) so issues are prevented rather than found late.
  • Build autonomous red‑teaming and threat hunting against our own products, using AI and automation to continuously probe for weaknesses instead of relying on point‑in‑time testing.
  • Own vulnerability management for everything we ship across our self‑managed enterprise platform and SaaS product - container images, third‑party dependencies, and first‑party code - automating detection, triage, and routing, and advancing remediation through reachability/exploitability analysis and attack‑surface reduction.
  • Own application and supply chain security tooling (SAST, SCA, DAST, container scanning), plus third‑party penetration testing and the Vulnerability Disclosure Program.
  • Be the security voice with customers and leadership , working directly with enterprise customers on posture and assurance, and reporting on product security in executive, customer, and audit conversations.
Some of the things we look for:
  • Bachelor's degree in Computer Science, Engineering, MIS, or equivalent practical experience.
  • 5-7 years of experience in application security, product security, software engineering with a security focus, or a related technical role.
  • Deep command of application and product security fundamentals, with the judgment to distinguish real exploitability from scanner noise.
  • Proven experience embedding security into the SDLC and getting engineering teams to actually adopt it - plus building and scaling processes that raise a program's overall maturity.
  • Demonstrated experience running vulnerability management for shipped software at scale, with strong knowledge of container/image security and JVM dependency and supply chain risk.
  • Offensive security experience and a drive to automate it: red‑teaming, or threat hunting against your own products.
  • Threat modeling experience on distributed systems and data platforms, and a strong bias toward automation, including using AI to scale security work.
  • Experience in enterprise B2B software and working directly with enterprise customers on security, ideally in regulated industries such as financial services.
  • Experience leading and mentoring engineers.

Starburst is dedicated to maintaining fair and equitable compensation practices. The salary range provided for this role reflects the minimum and maximum targets for candidates across all U.S. locations and could be inclusive of variable compensation, such as commission or bonus. All employees receive equity packages (ISOs) and have access to a comprehensive benefits offering. Actual compensation packages are determined based on relevant skills, experience, education and training, and specific work location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer | AI-Driven Security Automation
Senior Application Security Engineer | AI-Driven Security Automation

Starburst • Boston (MA)

On-site
USD 140,000 - 190,000
Equity packages
Comprehensive benefits
Senior Solution Architect
Senior Solution Architect

Starburst • San Francisco (CA)

On-site
USD 230,000 - 260,000
Senior Enterprise Account Executive, East
Senior Enterprise Account Executive, East

Starburst • Boston (MA)

On-site
USD 150,000 - 175,000
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital • Reno (NV)

On-site
USD 111,000 - 145,000
Profit-sharing bonus
401(k) with employer match
Comprehensive health insurance
Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Senior Security Engineer, Enterprise Security
Senior Security Engineer, Enterprise Security

United States Digital Space LLC • Chicago (IL)

On-site
USD 129,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3