Senior AppSec Engineer - Secure AI-Powered SaaS

United States Digital Space LLC

United States

Remote

USD 150,000 - 230,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Apollo.io in the United States is searching for a Senior Application Security Engineer to strengthen its secure software development lifecycle and reduce application risk across product, platform, and AI-powered features.

This senior-IC role blends code-level security work with cross-functional partnership, including reviews, threat modeling, tooling, and remediation; you will own security guardrails and collaborate with engineering teams to ship secure software.

Qualifications

  • 5+ years of software engineering or application security experience, with meaningful hands-on AppSec depth in modern SaaS environments.
  • Strong software development skills and the ability to read, write, and ship production code; Ruby experience is highly valuable, and Python or similar scripting ability is a plus.
  • Strong Linux and cloud fundamentals, ideally with experience in GCP-backed environments.
  • Deep familiarity with common AppSec issues, secure design, secure authentication and authorization patterns, vulnerability management, and developer security tooling.
  • Demonstrated ability to perform deep code review, penetration testing, and exploit-oriented validation, and to either fix vulnerabilities directly or work closely with engineers to land durable remediations that hold up against bypass attempts and variant analysis.
  • Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling through closure and verification.
  • Experience securing AI-powered systems or features, including AI API exposure, prompt and response guardrails, and abuse or data-exfiltration paths.

Responsibilities

  • Own and continuously improve secure SDLC for Apollo applications from design to deployment.
  • Perform application security reviews, threat modeling, and deep code-level analysis before launch.
  • Provide security architecture guidance to Engineering, Product, and IT teams.
  • Define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems.
  • Drive vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs.
  • Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities.
  • Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom.
  • Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities.
  • Apply clear, risk-based severity decisions using exploitability, data sensitivity, customer impact, and blast radius
  • Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise.
  • Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly.
  • Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment.
  • Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths.
  • Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely.
  • Engineering enablement and partnership: Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI-safety content.
  • Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly.
  • Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity.
  • Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision-making.
  • What Good Looks Like: Owns meaningful AppSec goals over a semi-annual or annual horizon and independently identifies the right solutions to ambiguous, open-ended problems.
  • Drives cross-team collaboration and operational improvements beyond isolated tickets or one-off reviews.
  • Makes informed decisions by balancing technical detail, business context, customer trust, and long-term risk.
  • Sets a high bar for ownership, communication, mentoring, and technical judgment, and helps raise the effectiveness of peers and partner teams.

Skills

5+ years software security
Ruby
Python
Linux
Cloud (GCP)
Code review
Penetration testing
Bug bounty
AI security
Security tooling/automation

Job description

Apollo.io in the United States is searching for a Senior Application Security Engineer to strengthen its secure software development lifecycle and reduce application risk across product, platform, and AI-powered features.

This senior-IC role blends code-level security work with cross-functional partnership, including reviews, threat modeling, tooling, and remediation; you will own security guardrails and collaborate with engineering teams to ship secure software.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer: Secure SDLC & AI Security
Senior AppSec Engineer: Secure SDLC & AI Security

Apollo.io • Raleigh (NC)

Hybrid
USD 190,000 - 237,000
Equity
401(k) plan
Paid holidays
+2
Senior AI Security Engineer: AppSec, Identity & APIs
Senior AI Security Engineer: AppSec, Identity & APIs

Identify Security • United States

On-site
USD 140,000 - 210,000
Senior Application Security Engineer
Senior Application Security Engineer

Apollo.io • Raleigh (NC)

Hybrid
USD 190,000 - 237,000
Equity
401(k) plan
Paid holidays
+2
Senior AppSec Engineer — AI-Driven SaaS Security Leader
Senior AppSec Engineer — AI-Driven SaaS Security Leader

Savvy Wealth • New York (NY)

On-site
USD 150,000 - 210,000
Equity
Unlimited PTO
Medical/Dental/Vision
+5
Senior AI-Native Backend Engineer
Senior AI-Native Backend Engineer

United States Digital Space LLC • United States

Remote
USD 150,000 - 230,000
Senior App Sec Engineer - Lead Secure AI Apps (Remote)
Senior App Sec Engineer - Lead Secure AI Apps (Remote)

Socket.dev • Northern (KY)

Hybrid
USD 167,000 - 231,000
Competitive compensation
Annual equity grants
401(k) with company match
+6
Senior AI-Powered AppSec Engineer
Senior AI-Powered AppSec Engineer

Cvent • Virginia (MN)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package
Senior AppSec Engineer: Secure AI/ML Platform, Equity
Senior AppSec Engineer: Secure AI/ML Platform, Equity

suno • Boston (MA)

On-site
USD 230,000 - 330,000
Company Equity Package
401(k) with 3% Employer Match & Roth 0
Medical, Dental, & Vision Insurance
+5
Senior AppSec Engineer - AI-Driven Security Tools
Senior AppSec Engineer - AI-Driven Security Tools

Gemini • United States

Hybrid
USD 140,000 - 200,000
Competitive starting pay
Discretionary annual bonus
New hire equity grant
+4
Senior App Security Engineer for AI Platform & CI/CD
Senior App Security Engineer for AI Platform & CI/CD

Amazon • Herndon (VA)

On-site
USD 178,000 - 227,000
Sign-on payments
Restricted stock units (RSUs)
Health insurance
+2