Senior Security Engineer: Threat Modeling & Static Analysis

Jobtailor

California (MO)

On-site

USD 150,000 - 210,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced security engineer focused on application security, static analysis, and threat modeling. You will work with product teams to surface and validate risks, author rules, and reduce manual effort while delivering measurable security outcomes.

The role requires strong coding knowledge across multiple ecosystems and hands-on experience with static analysis tooling like Semgrep or CodeQL. Collaboration and clear communication are essential for success.

Qualifications

  • 5+ years in security engineering, application security, or a closely related role.
  • At least 2 years in hands-on vulnerability-discovery capacity.
  • Deep familiarity with at least one major language ecosystem (Java, Python, JavaScript/TypeScript, Go, Ruby, or similar).
  • Ability to read and reason about code in other languages.
  • Working knowledge of static analysis tooling and custom rule authoring, tuning, and maintenance.
  • Experience with Semgrep, CodeQL, or equivalent.
  • Practical experience with threat modeling, authentication/authorization design, cloud security architecture, or supply chain security.
  • Ability to scope own work from a vague ask.
  • Excellent written and verbal communication.
  • A related technical degree required

Responsibilities

  • Surface real risk using agentic security systems, static analysis, manual review, and threat modeling.
  • Validate findings can be triggered manually or by extending tooling.
  • Reduce manual validation costs through engineering.
  • Author static analysis rules that block recurring vulnerability classes at PR time.
  • Contribute to intake pipelines for high-value findings into merge-blocking rules.
  • Advise on findings that meet rule-worthy thresholds.
  • Provide security consulting on difficult architectural questions.
  • Apply and extend scoping methodology across products.
  • Partner with product engineering teams to identify, validate, and prevent vulnerabilities.
  • Deliver measurable impact through detections shipped and vulnerabilities closed.

Skills

Security engineering
Vulnerability discovery
Static analysis tooling
Threat modeling
Programming languages

Education

Related Technical Degree

Tools

Semgrep
CodeQL

Job description

Jobtailor is seeking an experienced security engineer focused on application security, static analysis, and threat modeling. You will work with product teams to surface and validate risks, author rules, and reduce manual effort while delivering measurable security outcomes.

The role requires strong coding knowledge across multiple ecosystems and hands-on experience with static analysis tooling like Semgrep or CodeQL. Collaboration and clear communication are essential for success.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer: Threat Modeling & Secure SDLC
Application Security Engineer: Threat Modeling & Secure SDLC

CrowdStrike • United States

On-site
USD 120,000 - 180,000
Market-leading compensation
Wellness programs
PTO & holidays
+4
Remote Security Engineer II: Threat Modeling & Secure Coding
Remote Security Engineer II: Threat Modeling & Secure Coding

Amazon • Washington (IN)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
Remote Product Security Engineer: Threat Modeling
Remote Product Security Engineer: Threat Modeling

YipitData • United States

Remote
USD 162,000 - 198,000
401K match
Parental leave
Flexible vacation
+1
Senior Product Security
Senior Product Security

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Security Engineer II - Threat Modeling & Secure Coding
Security Engineer II - Threat Modeling & Secure Coding

Amazon • Virginia (IL)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
RSUs
+2
Senior AppSec Engineer: Threat Modeling & Secure SDLC
Senior AppSec Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
AppSec Security Engineer: Threat Modeling & Secure Coding
AppSec Security Engineer: Threat Modeling & Secure Coding

Socket.dev • Seattle (WA)

On-site
USD 136,000 - 184,000
Health insurance
RSUs (restricted stock units)
401(k) matching
+1
Lead Application Security Engineer: Threat Modeling & Secure SDLC
Lead Application Security Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • Burlington (VT), Northern (KY)

Hybrid
USD 120,000 - 160,000
Security Engineer II - Threat Modeling & Secure Code Review
Security Engineer II - Threat Modeling & Secure Code Review

Socket.dev • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+2
Senior Security Engineer — Threat Modeling & Secure Systems
Senior Security Engineer — Threat Modeling & Secure Systems

Amazon • Seattle (WA)

On-site
USD 178,000 - 227,000