Senior AppSec Engineer

Dream

United States

On-site

USD 120,000 - 160,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dream is seeking a Senior AppSec Engineer to plan, build, and support security across the organization. You’ll own application security throughout the SDLC, including security requirements, threat modeling, reviews, and production hardening.

You’ll partner with Security, Engineering, Platform, DevOps, and IT teams to reduce risk at scale, and report on metrics like control coverage and remediation timelines. Strong Python and automation skills are required.

Qualifications

  • 6+ years in security engineering, app security, or cloud security with hands-on ownership.
  • Deep expertise in application/security or cloud security with cross-domain capability.
  • Strong programming and automation skills; Python required; Go or Bash beneficial.

Responsibilities

  • Own application security across the SDLC from requirements to production hardening.
  • Perform threat modeling, secure design reviews, code reviews, and API testing.
  • Develop and report security metrics, remediation timelines, and baseline compliance.
  • Strengthen cloud/platform security with scalable controls and guardrails.
  • Collaborate with Security, Engineering, Platform, DevOps, and IT teams.

Skills

Security engineering
Threat modeling
Secure SDLC
Code review
Application security
Cloud security
Automation
Python programming
CI/CD security
Kubernetes security
Threat remediation

Tools

Terraform
OPA/Sentinel
CI/CD pipelines
SAST/DAST/SCA
Kubernetes
IAM/security tooling

Job description

Every nation has data. Few can protect it. Fewer still can act on it.

Dream is the sovereign AI and national cyber-defense company for governments.

We help nations secure their most critical systems, connect fragmented information at a national scale, and turn their most sensitive data into decisions, all fully sovereign.

This is more than a job. It's a Dream job, where you'll work at a global scale alongside some of the best AI researchers, cyber operators, and government experts in the world.

The mission only works if the company behind it does. This role keeps Dream running at the scale our work demands. And our work demands a uniquely global scale.

As a Senior AppSec Engineer, you'll plan, build, and support efforts to strengthen security across the organization. As part of our Security & Platform organization, you'll work across the software development lifecycle and the underlying cloud and platform environment.

You’ll own application security throughout the SDLC, including security requirements, threat modeling, secure design reviews, code reviews, application and API security testing, and production hardening. The role combines application security, cloud and platform security, and security automation. You’ll partner closely with Security, Engineering, Platform, DevOps, and IT teams to build secure‑by‑default systems and reduce risk at scale.

You’ll also define and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance. This is a hands‑on engineering role for someone who can move comfortably between architecture and threat modeling, code and API reviews, cloud and identity guardrails, CI/CD security controls, vulnerability remediation, and automation.

  • * Define, track, and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
  • * Own application security across the SDLC, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
  • * Strengthen cloud and platform security by implementing scalable security controls, identity guardrails, and secure‑by‑default practices.
  • * Partner closely with Security, Engineering, Platform, DevOps, and IT teams to reduce security risk and improve security practices across the organization.
  • * Designing controls for multi‑account or multi‑cloud environments using Terraform, policy‑as‑code technologies such as OPA or Sentinel, or automated remediation workflows.
  • * Experience running a Security Champions, bug bounty or responsible disclosure program, or delivering hands‑on secure engineering training.
  • * You'll translate technical risk into clear remediation guidance and influence engineering and leadership stakeholders through strong written and verbal communication.
  • * 6 years of relevant experience across security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering including substantial hands‑on security ownership.
  • * Deep expertise in either application/product security or cloud/platform security, with demonstrated hands‑on capability across the other domain.
  • * Strong programming and automation skills; proficiency in Python is required, with Go or Bash beneficial, together with practical CI/CD and infrastructure‑as‑code experience.
  • * Experience embedding security into the SDLC through threat modeling, secure design and code review, application/API testing and CI/CD controls, supported by strong knowledge of OWASP risks and secure design principles.
  • * Hands‑on experience securing at least one major public cloud platform, including IAM, workloads, networks, logging, organization‑level guardrails, containers/Kubernetes, and secrets and key management.
  • * Experience with relevant application and cloud security tooling, such as SAST, DAST, SCA, secrets scanning, CSPM/CNAPP, and cloud‑native security services.
  • * Hands‑on experience with Kubernetes admission controls, image and dependency scanning, supply‑chain security and CIS benchmarks.
  • * Familiarity with OWASP ASVS/SAMM, NIST SSDF/CSF, MITRE ATT&CK, SOC 2 or ISO 27001 control environments.
  • * Experience securing AI‑assisted development workflows, enterprise AI tools, agent‑based integrations, or MCP‑connected systems.

If you think this role doesn't fully match your skills but are eager to grow and break glass ceilings, we'd love to hear from you!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer – Cloud, SDLC & Automation
Senior Application Security Engineer – Cloud, SDLC & Automation

Dream • United States

On-site
USD 120,000 - 160,000
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Tysons (VA)

Hybrid
USD 120,000 - 160,000
Bonus
Competitive benefits
Senior Application Security Engineer – Vulnerability Operations
Senior Application Security Engineer – Vulnerability Operations

Veriipro • Jersey City (NJ)

On-site
USD 120,000 - 150,000