Staff Application Security Engineer

Jobtailor

Town of Florida (NY)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Application Security expert to own and evolve the Gemini SDLC guardrails for high‑risk applications and services. You will lead architecture reviews, threat modeling, secure code reviews, and penetration testing, and design AI‑driven security workflows across design, build, and deployment to reduce toil and strengthen protections.

You’ll also deliver hands‑on security training for engineers and participate in on‑call incident response and post‑incident

Qualifications

  • Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset.
  • Strong background in application security best practices and familiarity with vulnerabilities (e.g. SSRF, race conditions, privilege escalations).
  • Deep code review proficiency in Scala, Java, Go; hands-on experience in Python or Go for building.

Responsibilities

  • Own and evolve the Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert.
  • Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services.
  • Design and build AI agents throughout the SDLC for automated threat modeling during design, AI-driven secure code generation and review, and reducing AppSec toil.
  • Create and deliver hands‑on application security training to enable engineers at scale.
  • Participate in the Application Security on‑call rotation and lead post‑incident hardening.

Skills

Threat modeling
Secure code reviews
Penetration testing
Scala
Java
Go
Python
Code review
Vulnerability assessment
Cross-functional collaboration
Communication
OWASP Top 10

Job description

Own and evolve the Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert


Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services


Design and build AI agents throughout the SDLC for automated threat modeling during design, AI-driven secure code generation and review, and reducing AppSec toil


Create and deliver hands‑on application security training to enable engineers at scale


Participate in the Application Security on‑call rotation and lead post‑incident hardening


Requirements


  • Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset

  • Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)

  • Deep code review proficiency in Scala, Java, Go or other common languages, plus hands‑on experience in at least Python, Go, or similar for building. Comfortable reviewing production services written in other languages

  • Experience implementing custom detection and prevention application security controls to eliminate application security issues beyond OWASP Top 10

  • Familiarity with highly regulated environments (financial services, fintech, crypto, or equivalent) and ability to understand business objectives, business context, and security risk

  • Strong cross‑functional communication and collaboration (Security, Engineering, and Product)

  • Typically 7-10+ years of experience or equivalent impact in application security, product security, or similar roles


Core Competencies

Demonstrates expertise in application security, including threat modeling, secure code reviews, and penetration testing, while effectively communicating and collaborating across cross‑functional teams. Proficient in designing and implementing security controls in regulated environments, with a strong focus on reducing application security risks.


Highest-signal resume keywords


  • Application Security Best Practices

  • Threat Modeling

  • Penetration Testing

  • Code Review Proficiency in Scala, Java, Go

  • Cross-Functional Communication


ATS Optimization Keywords

Hard Skills


  • Threat Modeling

  • Secure Code Review

  • Penetration Testing

  • Application Security Controls

  • Scala

  • Java

  • Go

  • Python

  • Code Review

  • Vulnerability Assessment


Soft Skills


  • Cross-Functional Collaboration

  • Communication


Industry Keywords


  • Financial Services

  • Fintech

  • Crypto

  • Regulated Environments

  • OWASP Top 10

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Jobtailor • Atlanta (GA)

On-site
USD 120,000 - 160,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Application Security Engineer
Application Security Engineer

Jobtailor • San Francisco (CA)

On-site
USD 140,000 - 180,000
Senior Application Security Engineer
Senior Application Security Engineer

Jobtailor • North Carolina

On-site
USD 110,000 - 170,000
Staff Software Engineer, Product Security
Staff Software Engineer, Product Security

Jobtailor • California (MO)

On-site
USD 180,000 - 260,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Cybersecurity Engineer IV – Application Security
Cybersecurity Engineer IV – Application Security

Jobtailor • Illinois

On-site
USD 140,000 - 180,000
Senior Application Security Architect
Senior Application Security Architect

Jobtailor • Cary (NC)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Jobtailor • Colorado

On-site
USD 170,000 - 250,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000