Senior Application Security Engineer

Apollo.io

Raleigh (NC)

Hybrid

USD 190,000 - 237,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity
401(k) plan
Paid holidays
Flexible PTO
Parental leave

Job summary

Apollo.io is looking for a Senior Application Security Engineer II to enhance their secure software development lifecycle across products and platforms. This senior-level role involves performing application security reviews, threat modeling, and driving vulnerability management in a collaborative environment.

The ideal candidate will have over 5 years in application security or software engineering, and must demonstrate strong coding skills, particularly in Ruby and Python. The position is remote-friendly, allowing flexibility in work arrangements.

Qualifications

  • 5+ years of experience in software engineering or application security.
  • Strong software development skills with Ruby and Python experience.
  • Deep familiarity with common AppSec issues and secure design.

Responsibilities

  • Own and improve secure software development lifecycle for applications.
  • Perform application security reviews and threat modeling.
  • Drive vulnerability management and remediation.

Skills

Software engineering
Application security
Linux
Ruby
Python
Cloud fundamentals
Communication skills

Tools

AppSec tooling

Job description

Role Overview

The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI‑powered features. This role blends deep code‑level application security work with strong cross‑functional partnership. It includes application security reviews, threat modeling, AppSec tooling, findings triage and remediation follow‑through, external testing intake, and developer enablement. This role is calibrated at the L6 senior‑IC level: owning semi‑annual or annual goals, solving ambiguous problems with sound judgment, improving operational processes, and driving meaningful cross‑team collaboration and influence.

Key Responsibilities
Secure SDLC, design review, and threat modeling
  • Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment.
  • Perform application security reviews, threat modeling, and deep code‑level analysis for high‑impact product, platform, and AI features before launch.
  • Provide practical security architecture guidance to Engineering, Product, and IT teams.
  • Help define and maintain application‑security guardrails, secure design expectations, code review standards, and risk models for new and existing systems.
Vulnerability management and hands‑on remediation
  • Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs.
  • Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities.
  • Perform hands‑on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red‑team‑style exercises, to confirm remediations address the underlying issue rather than only the initial symptom.
  • Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities.
  • Apply clear, risk‑based severity decisions using exploitability, data sensitivity, customer impact, and blast radius.
Tooling, automation, and AI
  • Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise.
  • Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly.
  • Use AI to automate, transform, and scale security and engineering‑adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment.
  • Embed AI‑specific security checks into SSDLC reviews and code analysis, including input and output handling, AI‑exposed APIs, prompt and response guardrails, and abuse or data‑exfiltration paths.
  • Partner cross‑functionally on AI security requirements and controls so AI systems and AI‑powered features are designed, deployed, and operated securely.
Engineering enablement and partnership
  • Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI‑safety content.
  • Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly.
  • Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity.
  • Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision‑making.
What Good Looks Like at L6
  • Owns meaningful AppSec goals over a semi‑annual or annual horizon and independently identifies the right solutions to ambiguous, open‑ended problems.
  • Drives cross‑team collaboration and operational improvements beyond isolated tickets or one‑off reviews.
  • Makes informed decisions by balancing technical detail, business context, customer trust, and long‑term risk.
  • Sets a high bar for ownership, communication, mentoring, and technical judgment, and helps raise the effectiveness of peers and partner teams.
Required Skills & Experience
  • 5+ years of software engineering or application security experience, with meaningful hands‑on AppSec depth in modern SaaS environments.
  • Strong software development skills and the ability to read, write, and ship production code; Ruby experience is highly valuable, and Python or similar scripting ability is a plus.
  • Strong Linux and cloud fundamentals, ideally with experience in GCP‑backed environments.
  • Deep familiarity with common AppSec issues, secure design, secure authentication and authorization patterns, vulnerability management, and developer security tooling.
  • Demonstrated ability to perform deep code review, penetration testing, and exploit‑oriented validation, and to either fix vulnerabilities directly or work closely with engineers to land durable remediations that hold up against bypass attempts and variant analysis.
  • Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling through closure and verification.
  • Experience using AI‑assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale.
  • Experience securing AI‑powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring expectations.
  • Strong written and verbal communication, stakeholder management, and influencing skills across technical and non‑technical partners.
Preferred Qualifications
  • Experience supporting or leading security reviews for AI‑native products, internal agents, or AI‑assisted engineering workflows.
  • Experience improving secure‑by‑design practices and AppSec observability in a fast‑moving engineering organization.
  • Experience with security training, developer enablement, or security champions programs.
  • Relevant security certifications are a plus.
Example Success Outcomes
  • Improve the health and flow of AppSec findings by keeping prioritization, remediation, and verification moving within defined SLAs.
  • Complete recurring application reviews or threat models for important systems and features.
  • Increase engineering adoption of secure patterns, AppSec tooling, and security training.
  • Reduce manual toil and improve AppSec signal quality through targeted automation and responsible use of AI‑assisted workflows.
Pay Range

The listed Pay Range reflects the total cash compensation inclusive of annual base salary and annual bonus as applicable. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonus target and annual base salary for the role. This salary range may be inclusive of several career levels at Apollo and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role who are not located in the US may request the annual salary range for their location during the interview process.

Tier 1 Pay Range (San Francisco, New York City, Seattle): $218,000—$273,000 USD

Tier 2 Pay Range (All other US Locations): $190,000—$237,000 USD

Additional benefits

Additional benefits for this role may include: equity; company bonus or sales commissions/bonuses; 401(k) plan; at least 10 paid holidays per year, flex PTO, and parental leave; employee assistance program and wellbeing benefits; global travel coverage; life/AD&D/STD/LTD insurance; FSA/HSA and medical, dental, and vision benefits.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Application Security Engineer
Lead Application Security Engineer

Apollo • New York (NY)

On-site
USD 190,000 - 250,000
Outperform expectations
Challenge Convention
Champion Opportunity
+2
Senior AppSec Engineer - Secure SaaS & AI
Senior AppSec Engineer - Secure SaaS & AI

Embedded Shishya • United States

Remote
USD 190,000 - 273,000
Equity
Company bonus
401(k) plan
+7
Engineering Manager, Rep Experience
Engineering Manager, Rep Experience

United States Digital Space LLC • United States

On-site
USD 225,000 - 324,000
Equity
401(k) plan
Paid holidays
+6
Senior Software Engineer (Hybrid, San Francisco)
Senior Software Engineer (Hybrid, San Francisco)

Apollo • San Francisco (CA)

On-site
USD 195,000 - 358,000
Equity
Bonus/Commissions
401(k)
+7
Senior Software Engineer (Hybrid, San Francisco)
Senior Software Engineer (Hybrid, San Francisco)

Apollo.io • San Francisco (CA)

On-site
USD 195,000 - 358,000
Equity
401(k) plan
Paid holidays
+6
Principal Software Engineer (Hybrid, San Francisco)
Principal Software Engineer (Hybrid, San Francisco)

Apollo • San Francisco (CA)

On-site
USD 315,000 - 473,000
Equity
401(k) plan
Flex PTO & paid holidays
+2
Principal Software Engineer (Hybrid, San Francisco)
Principal Software Engineer (Hybrid, San Francisco)

Apollo.io • San Francisco (CA)

On-site
USD 315,000 - 473,000
Equity
Bonus
401(k) plan
+6
Senior Manager, Solution Consulting
Senior Manager, Solution Consulting

Apollo.io • San Francisco (CA)

On-site
USD 230,000 - 280,000
Equity
Bonus/Commissions
401(k)
+5
Senior AppSec Engineer - Secure AI-Powered SaaS
Senior AppSec Engineer - Secure AI-Powered SaaS

United States Digital Space LLC • United States

Remote
USD 150,000 - 230,000
Senior Manager, Finance & Strategy - Go-To-Market
Senior Manager, Finance & Strategy - Go-To-Market

Apollo Group • Northern (KY)

Hybrid
USD 159,000 - 228,000
equity
company bonus or sales commissions/bon
401(k) plan
+1