Senior Application Security Engineer

Sift

California (MO)

Hybrid

USD 180,000 - 230,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Equity

Job summary

Sift is hiring a security-first software engineer to build and own the security of production systems. You’ll drive threat modeling, secure-by-default patterns, and tooling across distributed architectures that power critical hardware platforms.

You will embed SAST/SCA tooling into developer workflows, ensure dependency integrity, and guide security decisions with engineering partners. This role involves on-premise or air-gapped considerations and collaboration across teams.

Qualifications

  • 5+ years building production software with direct security ownership
  • Fluency reading and reviewing Go or Rust
  • Strong grounding in application security: web/API auth and cryptography
  • Hands-on experience embedding security tooling into CI/CD
  • Track record building security tooling used by teams
  • Clear communication with engineers and leadership about risk

Responsibilities

  • Secure-by-default guardrails: patterns, libraries, and standards for authentication and cryptography
  • Own dependency integrity, artifact signing, and build-pipeline trust for self-managed deployments
  • Threat modeling and secure design for distributed systems
  • Own appsec toolchain in CI/CD: SAST, SCA, secret scanning, fuzzing
  • Raise engineering security fluency through design reviews and documentation

Skills

Production security ownership
Go or Rust
Threat modeling
Security tooling
Communication

Tools

SAST
SCA
Secret scanning

Job description

About Sift

Sift is the data infrastructure platform for hardware engineering teams. We turn high-frequency telemetry into engineering insights for mission-critical machines: rockets, satellites, autonomous vehicles, energy systems, and defense platforms. Founded by former SpaceX engineers, we are building the review and analysis layer for the AI era of physical systems.

About Sift

Sift is the data infrastructure platform for hardware engineering teams. We turn high-frequency telemetry into engineering insights for mission-critical machines: rockets, satellites, autonomous vehicles, energy systems, and defense platforms. Founded by former SpaceX engineers, we are building the review and analysis layer for the AI era of physical systems.

In This Role, You’ll
  • Secure-by-default guardrails: Build the patterns, libraries, and standards for authentication, authorization, input handling, and cryptography that make whole classes of vulnerability hard to introduce. Ensure the secure path is the path of least resistance.
  • Software supply chain: Own dependency integrity, artifact signing, and build-pipeline trust. This matters especially for the self-managed and air-gapped deployments our customers run.
  • Threat modeling and secure design: Partner with engineering teams on new features and architectural changes across a distributed, polyglot system, and turn the results into concrete design decisions.
  • Developer-facing security tooling: Own the appsec toolchain in CI/CD: SAST, software composition analysis, secret scanning, and fuzzing. Tune it so developers get findings worth acting on, then work with the owning teams to drive remediation.
  • Raise engineering’s security fluency: Make security knowledge something engineers pick up from design reviews, documentation, and working with you, not something they have to come ask for.
The Skillset You’ll Bring
  • 5+ years building production software, including direct security ownership of a codebase you shipped. You are a software engineer first, applying that skill to security.
  • Fluency reading and reviewing a compiled systems language, with depth in Go or Rust.
  • Strong grounding in application security: web and API vulnerability classes, authentication and authorization patterns, and applied cryptography, applied through threat modeling and design review on distributed systems.
  • Hands‑on experience embedding security tooling (SAST, SCA, secret scanning) into developer workflows and CI/CD, tuned for signal over noise.
  • A track record of building security tooling or libraries that other teams actually adopted.
  • Clear communication with engineers and leadership. You can explain risk and tradeoffs to people who don’t live in security.
Bonus Points
  • Experience securing software that ships to customer-controlled, on-premise, or air-gapped environments.
  • Familiarity with software supply chain tooling and standards (Sigstore, SLSA, SBOM generation).
  • Fuzzing native or high-throughput data paths.
  • Exposure to regulated environments such as defense or aerospace.
Location

SIFT’s headquarters is in Marina Del Rey, CA (Next to LAX). We collaborate in person twice a week—on Mondays and Thursdays—and come together for a full week every two months. We are open to relocating candidates to LA or working from our San Francisco office for the right candidate.

Salary range

$180,000 - $230,000 per year. Plus equity and benefits.

Eligibility

U.S. Citizenship Required: This position requires U.S. citizenship due to the nature of certain customer environments, security requirements, and access obligations associated with the role.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer, Security Infrastructure
Software Engineer, Security Infrastructure

Sift • California (MO)

Hybrid
USD 170,000 - 220,000
Equity
Benefits
Software Engineer, Security Infrastructure
Software Engineer, Security Infrastructure

Sift Stack, Inc. • California (MO)

Hybrid
USD 170,000 - 220,000
Senior Security Engineer
Senior Security Engineer

Sift • San Francisco (CA), Seattle (WA)

Hybrid
USD 140,000 - 210,000
Senior Software Engineer, Infrastructure
Senior Software Engineer, Infrastructure

Sift Stack, Inc. • El Segundo (CA)

Hybrid
USD 170,000 - 220,000
Software Engineer, Infrastructure
Software Engineer, Infrastructure

Sift Stack, Inc. • California (MO)

On-site
USD 150,000 - 200,000
Software Engineer, Infrastructure
Software Engineer, Infrastructure

Sift • California (MO)

Hybrid
USD 150,000 - 200,000
Equity
Comprehensive benefits
Application Software Engineer
Application Software Engineer

Sift Stack, Inc. • California (MO)

Hybrid
USD 105,000 - 150,000
Equity in the company
Competitive benefits package
Software Engineer, Infrastructure
Software Engineer, Infrastructure

Sift • San Francisco (CA)

On-site
USD 150,000 - 200,000
Software Engineer, Full Stack
Software Engineer, Full Stack

Sift • California (MO)

Hybrid
USD 150,000 - 200,000
Staff Software Engineer, Data
Staff Software Engineer, Data

Sift Stack, Inc. • San Francisco (CA)

Hybrid
USD 200,000 - 250,000
Equity
Benefits
Flexible work environment