Enable job alerts via email!

Senior Application Security Engineer

Drata

United States

Remote

USD 166,000 - 207,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a Senior Application Security Engineer to serve as an internal security expert. This full-time role involves performing security assessments, developing security policies, and collaborating with cross-functional teams. Candidates should have a Bachelor's degree in Computer Science and at least 5 years of experience in application security or software development, with a focus on secure coding practices and web application security.

Benefits

90-100% paid premiums for medical, dental, and vision plans
Flexible vacation policy
$500 annually towards professional development opportunities
16 Weeks Paid Parental Leave
Work from home allowance of $1,000 annually
401K

Qualifications

  • 5+ years of experience in application security or software development.
  • Experience with common web application vulnerabilities.
  • Strong knowledge of web development frameworks, including REST and React.

Responsibilities

  • Conduct security assessments of applications, including code reviews and penetration testing.
  • Develop and implement security policies to protect Drata’s data.
  • Lead vulnerability management and incident response for security incidents.

Skills

Secure coding practices
Web application security
Threat modeling
Problem-solving
Analytical skills
Verbal communication
Written communication

Education

Bachelor's degree in Computer Science or related field

Tools

Burp Suite
OWASP ZAP
Datadog

Job description

Join to apply for the Senior Application Security Engineer role at Drata

Join to apply for the Senior Application Security Engineer role at Drata

Get AI-powered advice on this job and more exclusive features.

Drata’s Senior Application Security Engineer is Drata’s full time in-house resident hacker, responsible for identifying and mitigating application and product security of Drata’s Trust Management Platform. This scope includes identifying and mitigating application and product security risks, implementing application and product security controls, providing guidance to development teams to help ensure secure coding practices, and directly assisting in changes needed to mitigate these risks and vulnerabilities.

What you’ll do:

  • Be Our Resident Hacker and Internal Red Team — Hack All The Things! Conduct security assessments of applications, including code reviews, penetration testing, and red team exercises. Work with external partners to accomplish these things as part of annual and ongoing assessments.
  • Set Application Security Expectations: Develop and implement security policies, standards, guidelines, and procedures to ensure the safety and protection of Drata’s data, applications, platform, and supporting systems. Collaborate with development teams to integrate security into the software development life cycle (SDLC).
  • Build Security Into Everything: Work closely with internal teams to ensure application security is integrated throughout the software development lifecycle, system administration, and business operations. Collaborate with cross-functional teams to ensure security compliance across all departments and systems. Work with Drata’s product and engineering teams during design to help ensure security is baked into the application.
  • Vulnerability Management: Conduct regular vulnerability assessments, and identify and mitigate security vulnerabilities in applications in a timely manner.
  • Application Security Incident Response: Lead investigation and response efforts for application-level security incidents.
  • Foster Trusted Partnerships Across Engineering: Build strong, collaborative relationships with application and platform teams. Act as an embedded security partner—offering practical, empathetic guidance to drive secure development without blocking innovation.
  • Deploy and Advance Application Security Capabilities: Continuously research, evaluate, and implement cutting-edge application security technologies.
  • Reporting: Prepare and present regular application security reports to management. Communicate application security vulnerabilities and remediation efforts to relevant stakeholders.

What you’ll bring:

  • Bachelor's degree in Computer Science or related field (or equivalent experience)
  • 5+ years of experience in application security, software development, or related field
  • Strong knowledge of secure coding practices, web application security, and threat modeling
  • Experience with common web application vulnerabilities and remediation techniques
  • Strong knowledge of web application development frameworks and technologies including REST, Node, Javascript, Typescript, and React
  • Experience with security testing tools such as Burp Suite and OWASP ZAP
  • Experience with application observability tools such as Datadog
  • Strong problem-solving and analytical skills
  • Strong verbal and written communication skills

Benefits:

  • Healthcare: 90-100% paid premiums for medical, dental, and vision plans for employee and dependents + on demand health care concierge
  • HSA, FSA, & DCFSA: Pre-tax savings plans for healthcare and dependent care, with up to a $600 annual employer contribution to the HSA plan (if enrolled in HSA medical plan)
  • 100% paid short and long term disability plus life + AD&D benefits
  • Learning & Development: $500 annually towards professional development opportunities + $250 annually towards personal development opportunities
  • Flexible Time Off: Flexible vacation policy for strong, fully charged batteries
  • 16 Weeks Paid Parental Leave: An inclusive policy to ensure you have time with your newborn, newly adopted, or foster child
  • Work Remotely: Flexible hours and work from home + $1,000 annually to cover necessary business related items for your home office
  • 401K: Reach your financial goals while reducing your taxes

This role will receive a competitive base salary, benefits, and stock, typically in the form of Restricted Stock Units (RSUs). The applicable salary range for each US-based role is based on where the employee works and is aligned to one of 3 tiers based on the cost of labor for that geographic area. The expected salary ranges for this role are below, subject to change.

Tier 1: $166,840 - $206,200

Tier 2: $150,280 - $185,600

Tier 3: $133,535 - $165,000

You can view which tier applies to where you plan to work here. A variety of factors are considered when determining someone’s leveling and compensation–including a candidate’s professional background and experience. These ranges may be modified in the future and final offer amounts may vary from the amounts listed above.

Drata is on a mission to serve as the trust layer between great companies.

Drata is a trust management platform that uses AI-driven automation to modernize governance, risk, and compliance, helping thousands of businesses develop a more secure, proactive, and risk-aware organization to continuously maintain trust with customers.

We all recognize the importance of earning and keeping the trust of our customers when it comes to protecting their data. We know how burdensome achieving and maintaining a strong GRC posture can be with the rise in compliance regulations. It’s a manual, redundant, error-prone, and unscalable process - and it only grows more complex and expensive over time.

Our team of SaaS, security, compliance, and audit experts have built a better way - with automation

Employment at Drata is based solely upon individual merit and qualifications directly related to professional competence. We strictly prohibit unlawful discrimination or harassment on the basis of race, color, religion, veteran status, national origin, ancestry, pregnancy status, sex, gender identity or expression, age, marital status, mental or physical disability, medical condition, sexual orientation, or any other characteristics protected by law. We also make reasonable accommodations to meet our obligations under laws protecting the rights of the disabled.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Software Development

Referrals increase your chances of interviewing at Drata by 2x

Sign in to set job alerts for “Senior Application Security Engineer” roles.
Senior Application Security Engineer (Remote - USA)

United States
$192,200.00
-
$225,810.00
2 weeks ago

Senior Application Security Engineer (Remote - USA)

Concord, NH
$192,200.00
-
$225,810.00
5 hours ago

Senior Application Security Engineer - Secure Code Analysis
Sr. Application Security Engineer (Remote)
Sr. Application Security Engineer (Remote)

United States
$162,900.00
-
$191,600.00
17 hours ago

Senior Security Engineer, Application Security

United States
$150,000.00
-
$200,000.00
3 weeks ago

United States
$125,000.00
-
$170,000.00
2 weeks ago

Palo Alto, CA
$180,000.00
-
$200,000.00
2 weeks ago

Senior Security Engineer II - Application Security, Remote

Washington, DC $150,000 - $180,000 2 weeks ago

United States $180,000 - $220,000 6 days ago

Senior Security Engineer, Application & Cloud

United States $150,000 - $180,000 1 week ago

Senior Security Engineer II, Application Security

United States $123,200 - $184,800 1 day ago

United States $110,000 - $125,000 1 week ago

Full Stack Senior Software Engineer - Java/Kotlin

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Security Engineer, Application & Cloud

Rad AI

null null

Remote

Remote

USD 150,000 - 180,000

Full time

8 days ago

Senior Application Security Engineer

Headway

null null

Remote

Remote

USD 198,000 - 268,000

Full time

13 days ago

Senior Application Security Engineer

Sprout Social

null null

Remote

Remote

USD 146,000 - 220,000

Full time

16 days ago

Senior Application Security Engineer

Davita Inc.

null null

Remote

Remote

USD 146,000 - 242,000

Full time

18 days ago

Senior Application Security Engineer (Remote - USA)

Lensa

Salt Lake City null

Remote

Remote

USD 192,000 - 226,000

Full time

Today
Be an early applicant

Senior Application Security Engineer (Remote - USA)

Lensa

Nashville null

Remote

Remote

USD 192,000 - 226,000

Full time

Yesterday
Be an early applicant

Senior Application Security Engineer (Remote - USA)

Lensa

Saint Paul null

Remote

Remote

USD 192,000 - 226,000

Full time

Yesterday
Be an early applicant

Senior Application Security Engineer (Remote - USA)

Lensa

Salt Lake City null

Remote

Remote

USD 192,000 - 226,000

Full time

Yesterday
Be an early applicant

Senior Application Security Engineer

Ohiox

null null

Remote

Remote

USD 163,000 - 227,000

Full time

30+ days ago