Sr. Security Engineer

Lucid

Salt Lake City (UT)

On-site

USD 150,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Remote or office options

Job summary

Lucid Software seeks a Senior Application Security Engineer to be embedded in the development lifecycle, partnering with engineering and product teams to build security in from the start. You will lead reviews, shape SSDLC, and mentor engineers while balancing innovation and risk.

The role supports a hybrid workplace and collaboration across product security and leadership. Ideal candidates bring 5+ years of security and software experience, strong communication skills, and practical knowledge

Qualifications

  • 5+ years in software engineering or application security within SaaS.
  • Experience securing web applications built on modern frameworks and AWS.
  • White-box penetration testing experience.
  • Strong understanding of SSDLC principles and secure development programs.

Responsibilities

  • Conduct security architecture and design reviews for new features and surface risk early.
  • Drive a risk-based approach to application security and prioritize vulnerabilities by business impact.
  • Serve as subject matter expert on application security for product, engineering, legal, and leadership.
  • Mentor engineers on secure development practices and foster a security-aware culture.
  • Build partnerships with product and engineering as their primary security resource across the SDLC.
  • Mature SSDLC with secure coding standards and education for developers.
  • Ensure AI tools and processes operate within acceptable risk levels.
  • Lead product design reviews to embed security in feature design.
  • Develop scalable security tooling and automations for CI/CD pipelines to reduce risk.
  • Lead and train engineers in Lucid’s security champions program.

Skills

Security leadership
Cloud security
OSWASP Top 10
SDLC security
Communication

Education

Bachelor's degree in Computer Science or related field

Tools

AWS
CI/CD tooling
Static/Dynamic analysis tools

Job description

Lucid Software is the leader in AI-driven work acceleration, helping teams see and build the future by turning ideas into reality. Its products include the Lucid Visual Collaboration Suite (Lucidchart and Lucidspark) and airfocus. The Lucid Visual Collaboration Suite, combined with powerful accelerators for cloud and process transformation, empowers organizations to streamline work, foster alignment, and drive business transformation at scale. We hold true to our core values: innovation in everything we do, passion & excellence in every area, individual empowerment, initiative and ownership, and teamwork over ego. At Lucid, we value diverse perspectives and are dedicated to creating an environment and culture that is respectful and inclusive for everyone. Lucid is a hybrid workplace. We promote a healthy work-life balance by allowing employees to work remotely, from one of our offices, or a combination of the two depending on the needs of the role and team.
As a Senior Application Security Engineer at Lucid, you will be a trusted security partner embedded in the heart of our development lifecycle. You'll work closely with engineering, product, and corporate teams to build security in from the start.

Lucid's customers trust us with their data, and that trust is foundational to our mission. A successful Senior Application Security Engineer combines deep technical knowledge with strong relationship-building skills, enabling product teams to move fast without taking on undue risk.

Responsibilities:

  • Conduct thorough security architecture and design reviews for new and evolving product features, surfacing risk early and recommending practical mitigations.
  • Drive a risk-based approach to application security, helping teams understand and prioritize vulnerabilities by business impact.
  • Serve as a subject matter expert on application security topics for product, engineering, legal, and leadership stakeholders.
  • Mentor engineers across the organization on secure development practices, fostering a culture where security is everyone's responsibility.
  • Build and maintain strong, collaborative partnerships with product and engineering teams, serving as their primary security resource and advocate throughout the software development lifecycle.
  • Mature Lucid's Secure Software Development Lifecycle (SSDLC), including secure coding standards, security requirements, and developer security education.
  • Ensure AI tools and processes are implemented within acceptable risk limits.
  • Lead product design reviews to ensure security considerations are inherent in feature design.
  • Develop and maintain scalable security tooling and automation to integrate security controls into CI/CD pipelines with a focus on reducing risk over implementing tools.
  • Lead and train engineers in Lucid’s security champions program.

Requirements:

  • 5+ combined years of experience in software engineering, application security, product security, or a closely related field within a SaaS environment.
  • Proven track record of building trusted, effective relationships with product and engineering teams.
  • Experience securing web applications built on modern frameworks and cloud-native architectures (particularly AWS).
  • White-box penetration testing experience.
  • Strong understanding of SSDLC principles and experience implementing or maturing secure development programs.
  • Ability to conduct meaningful security architecture and design reviews, with a focus on identifying risk early in the development process.
  • Solid understanding of common application vulnerabilities and attack techniques (OWASP Top 10, API security, authentication/authorization flaws, etc.).
  • Experience integrating security tooling into modern CI/CD pipelines.
  • Risk-focused mindset: able to articulate security risk in business terms and help teams make informed, pragmatic decisions while avoiding security theater.
  • Familiarity with AI security risks and emerging attack surfaces, including securing agentic systems, MCP, and LLM-powered workflows against new and evolving threats.
  • Strong written and verbal communication skills; equally comfortable in a design review with engineers and a risk conversation with leadership.

Preferred Qualifications:

  • Development experience in modern tech stacks.
  • Practical knowledge of relevant security frameworks and compliance standards (e.g., OWASP ASVS, NIST 800-53, SOC 2, GDPR).
  • Relevant certifications such as OSCP, BSCP, GWEB, PNPT, or similar hands-on security-focused certifications.
  • Experience with bug bounty program management.
  • Bachelor's degree in Computer Science, Information Security, or a related field.

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Lucid Software’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Security Engineer
Sr. Security Engineer

Lucid • Raleigh (NC)

Hybrid
USD 140,000 - 190,000
Hybrid work model
Remote work flexibility
Security Analyst
Security Analyst

Lucidsoftware • Salt Lake City (UT)

On-site
USD 70,000 - 110,000
Security Analyst
Security Analyst

Lucidsoftware • Raleigh (NC)

On-site
USD 70,000 - 90,000
Security Analyst – Hybrid/Remote Risk & Compliance
Security Analyst – Hybrid/Remote Risk & Compliance

Lucidsoftware • Raleigh (NC)

Hybrid
USD 70,000 - 90,000
Security Analyst
Security Analyst

Lucid • Raleigh (NC)

On-site
USD 70,000 - 100,000
Remote Senior Application Security Engineer - SSDLC & AI Risk
Remote Senior Application Security Engineer - SSDLC & AI Risk

Lucid • Salt Lake City (UT)

Hybrid
USD 150,000 - 210,000
Hybrid work model
Remote or office options
Sr. TPM Cybersecurity
Sr. TPM Cybersecurity

Lucid Motors • Southfield (MI)

On-site
USD 120,000 - 180,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
Sr. TPM Cybersecurity
Sr. TPM Cybersecurity

Lucid Motors USA, Inc. • Newark (CA)

On-site
USD 150,000 - 210,000
Medical, dental, vision
401(k) retirement plan
Paid time off
+2
Sr. TPM Cybersecurity
Sr. TPM Cybersecurity

Lucid Motors USA, Inc. • Southfield (MI), Northern (KY)

On-site
USD 130,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+6
Sr. TPM Cybersecurity Lucid Motors · Southfield, MI Full-time · On-site — 14 minutes ago
Sr. TPM Cybersecurity Lucid Motors · Southfield, MI Full-time · On-site — 14 minutes ago

Emploive • Southfield (MI), Northern (KY)

Hybrid
USD 150,000 - 210,000
Medical, dental, and vision insurance
Life and disability coverage
Paid time off
+3