Senior Security Engineer: Threat Modeling & Patches

Stravexa Private Limited

United States

On-site

USD 140,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Stravexa Private Limited is seeking a Senior Security Engineer to bridge automated security scanning with product engineering teams. You will lead threat modeling, vulnerability triage, exploitability validation, and automated patch QA to drive security issues through production closure.

The role requires hands-on security engineering, strong programming in C++, Go, Java, or Python, and deep knowledge of CWE/CVE, OWASP Top 10, and secure coding practices.

Qualifications

  • Strong hands-on experience in Application/Product Security Engineering.
  • Experience with Threat Modeling, including trust boundaries, attack surfaces, data flows, STRIDE/PASTA.
  • Strong knowledge of CWE, CVE, OWASP Top 10, vulnerability severity, and remediation SLAs.
  • Ability to reproduce vulnerabilities, build PoCs, and create test harnesses.
  • Strong programming skills in at least 2 of: C++, Go, Java, Python.
  • Strong debugging and source-code review experience.
  • Knowledge of secure coding practices, input validation, boundary checking, and safe memory access.
  • Experience validating automated/AI-generated security patches, including code-diff review and regression testing.
  • Ability to work directly with product engineering teams and drive vulnerabilities through verified resolution.

Responsibilities

  • Bridge automated security scanning/remediation with product engineering teams.
  • Perform threat modeling, vulnerability triage, and exploitability validation.
  • Lead automated patch QA and drive security issues through production closure.
  • Reproduce vulnerabilities, build PoCs, and review code diffs for patches.

Skills

Threat modeling
Vulnerability triage
Exploitability validation
Automated patch QA
Secure coding practices
C++
Go
Java
Python
Code review

Job description

Stravexa Private Limited is seeking a Senior Security Engineer to bridge automated security scanning with product engineering teams. You will lead threat modeling, vulnerability triage, exploitability validation, and automated patch QA to drive security issues through production closure.

The role requires hands-on security engineering, strong programming in C++, Go, Java, or Python, and deep knowledge of CWE/CVE, OWASP Top 10, and secure coding practices.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Stravexa Private Limited • United States

On-site
USD 140,000 - 210,000
Application Security Engineer: Threat Modeling & Automation
Application Security Engineer: Threat Modeling & Automation

Embedded Shishya • United States

Remote
USD 180,000 - 200,000
Flexible PTO
Learning & Development stipend
Headspace access
+2
Product Security Engineer - Threat Modeling & Secure Dev
Product Security Engineer - Threat Modeling & Secure Dev

Insight Global • North Reading (MA)

Hybrid
USD 70,000 - 117,000
Product Security Engineer: Threat Modeling & Auto-Patcher
Product Security Engineer: Threat Modeling & Auto-Patcher

Noblesoft Technologies Inc. • California (MO)

Hybrid
USD 150,000 - 230,000
Security Engineer: Offensive Testing & Product Threat Modeling
Security Engineer: Offensive Testing & Product Threat Modeling

Xage Security • Palo Alto (CA)

On-site
USD 170,000 - 200,000
Senior AppSec Engineer — Threat Modeling & Defense
Senior AppSec Engineer — Threat Modeling & Defense

ButterflyMX • United States

On-site
USD 120,000 - 170,000
Medical/Dental/Vision
401(k) with match
Paid holidays and time off
+4
Senior AppSec Engineer - Vulnerability & Secure Coding
Senior AppSec Engineer - Vulnerability & Secure Coding

Bridge Technologies and Solutions • Cherry Hills Village (CO)

On-site
USD 80,000 - 110,000
Lead Application Security Engineer: Threat Modeling & Secure SDLC
Lead Application Security Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • Burlington (VT), Northern (KY)

Hybrid
USD 120,000 - 160,000
Application Security Engineer - Threat Modelling & Secure Coding
Application Security Engineer - Threat Modelling & Secure Coding

Open Systems Technologies • New York (NY)

On-site
USD 150,000 - 200,000
Cyber Security Engineer: Threat Modeling & Pen Testing
Cyber Security Engineer: Threat Modeling & Pen Testing

S&P Global • New York (NY)

On-site
USD 70,000 - 90,000