Senior Application Security Engineer

SentinelOne, Inc.

United States

Remote

USD 140,000 - 230,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision coverage
Unlimited Time Off
Paid Holidays
401K
Volunteer Time Off

Job summary

SentinelOne is seeking a senior software security consultant to review code and guide customers on C, C++, Rust, and Java security assessments. You’ll validate findings from agentic scanning, translate technical risk into business impact, and help scale our AI-powered code analysis practice.

You will engage with Wayfinder Frontier AI Services customers end-to-end, scope work, present results to executives, and collaborate with threat hunters and engineering teams to reduce false positives and

Qualifications

  • Proficiency in at least two of C, C++, Rust, and Java with secure-coding focus.
  • 5+ years in application security or product security with strong software background.
  • Expertise in git-based source control and CI/CD security controls.
  • Demonstrated threat modeling across the secure SDLC.
  • Knowledge of OWASP Top 10, CWE Top 25, and modern auth (SAML/OIDC/JWT).
  • Experience delivering executive-level debriefs and customer-facing engagements.
  • Experience authoring SAST rules and AI-assisted code review workflows.

Responsibilities

  • In this role, you’ll be trusted to advise customers on C/C++/Rust/Java security assessments.
  • Review and triage findings from our code scanning pipeline; validate true positives.
  • Present results to diverse technical and leadership audiences and map risk to business impact.
  • Author and maintain SAST rule packs; partner with AI/ML engineers to improve scanning.
  • Support customer engagements end-to-end and scope work for Wayfinder Frontier AI Services.
  • Collaborate with engineering and threat hunters to reduce false positives.

Skills

C/C++/Rust/Java
Application security
Git CI/CD
Threat modeling
OWASP Top 10
CWE Top 25
OAuth/OIDC/JWT
ASVS Level 4
Executive communication
SAST rules
AI-assisted review
AI acceleration
Customer engagements
Compliance mapping
Security research certs
Reverse engineering
Python/Node.js

Tools

Ghidra
IDA Pro
Binary Ninja
Express (Node.js)

Job description

  • We’re looking for people who are relentlessly curious and committed to continuous learning
  • AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts
  • Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes
  • SentinelOne recently launched Wayfinder Frontier AI Services — a new customer-facing offering that pairs frontier AI models with our most seasoned offensive and defensive experts
  • The service extends our Wayfinder portfolio (Threat Hunting, MDR Essentials, MDR Elite, Incident Readiness & Response) into proactive, AI-accelerated exposure management
  • In this role, you’ll do more than review code — you’ll become the trusted advisor customers turn to on C, C++, Rust, and Java source code assessments
  • You’ll work directly on top of the output of our agentic code scanning pipeline, validate findings with human judgment, deliver results to diverse technical and leadership audiences, and shape the methodology that scales the practice
  • Support Wayfinder Frontier AI Services customer engagements end-to-end, scope the work, deliver the technical findings, and present results to executive and technical stakeholders
  • Review and triage findings from our agentic code scanning pipeline against customer C, C++, Rust, and Java codebases; validate true positives, eliminate noise, and ensure every finding that reaches the customer is a decision they can act on
  • Conduct deep code review across C, C++, Rust, and Java code and common frameworks
  • Present findings to stakeholders, translate technical risk into business impact, and map exposures into end-to-end exploitation chains
  • Author and maintain SAST rule packs that scale across the customer base, and partner with our AI/ML engineers to improve our agentic scanning engine
  • Provide expert remediation guidance to customer development teams and validate fixes through follow-up review
  • Work closely with our engineering teams to enhance our agentic code scanning pipeline and reduce false positives
  • Collaborate with team members and software-focused threat hunters to elevate team technical standards
Benefits
  • Medical, dental, and vision coverage
  • Employee assistance program
  • Gym reimbursement
  • Incentive-based challenges
  • Mental health and mindfulness
  • Unlimited Time Off
  • Grandparent Leave
  • Volunteer Time Off
  • Paid Sick Time
  • Paid Holidays
  • 16 weeks Gender-Neutral Parental Leave
  • Restricted Stock Unit Program
  • Flexible Spending Accounts
  • Life Insurance
  • Short and Long Term Disability Insurance
  • 401K
  • Team building activities
  • Celebrations and social gatherings
  • Community volunteering events
  • Global all hands and local town hall events

Proficiency in at least two of C, C++, Rust, and Java, with a strong understanding of vulnerabilities and secure coding methodologies5+ years in application security or product security with a strong software development backgroundFluency with Git-based source control and CI/CD pipelines, including build-pipeline security controls, runner hardening, and release-gate enforcementStrong threat modeling experience throughout the secure SDLCStrong knowledge of OWASP Top 10, CWE Top 25, and modern authentication infrastructure (SAML, OAuth, OIDC, JWT internals); experience driving an application through ASVS Level 4 verification is a plusProficiency in at least two of C, C++, Rust, and Java, having previously identified and explained vulnerabilities at the framework level, not just the application levelA proven track record translating complex findings into technical and executive-level debriefs; excellent written and verbal communication is essentialHands-on experience authoring custom static-analysis rules and queries for modern SAST engines; familiarity with AI-assisted code review workflows and validating findings produced by automated and agentic analysis pipelinesExperience with AI-accelerated development or code scanning methodologiesExperience delivering customer-facing or consulting-style engagements end-to-end, comfortable in a distributed remote organizationFamiliarity with SOC 2, ISO 27001, or FedRAMP control mappingOSWE, CSSLP, GWAPT, published CVEs, or conference talksReverse engineering of compiled C, C++, Rust, Java (IDA Pro, Binary Ninja, Ghidra)Working depth in Python (Django/Flask) and Node.js (Express) for cross-language reviews

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Vulnerability Analyst
Application Security Vulnerability Analyst

Perennial Resources International • New York (NY)

On-site
USD 110,000 - 160,000
Application Security Engineer
Application Security Engineer

Akaasa Technologies • North Carolina

Hybrid
USD 140,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Dallas (TX)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Boston (MA)

On-site
USD 140,000 - 190,000
Professional growth
Competitive USD-based compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Tampa (FL)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Texas City (IL)

Hybrid
USD 140,000 - 200,000
Professional growth
Competitive compensation (USD)
Exciting projects with Fortune 500s
+1
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • West Palm Beach (FL)

Hybrid
USD 140,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Irving (IA)

On-site
USD 130,000 - 170,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine • Boca Raton (FL)

Hybrid
USD 120,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1