Staff Application Security Engineer

Engine

United States

Remote

USD 170,000 - 260,000

Full time

29 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Engine is seeking a highly-skilled Staff Security Engineer to own the security and integrity of our applications and systems. You will build and run our vulnerability management pipeline and lead our application security program.

You will collaborate with engineering to ensure best practices, tackle complex repairs, and keep the Engine platform fast and secure. This role requires independence, clear communication, and a proactive security mindset.

Qualifications

  • Proficient in at least one major language (Ruby/Java/Python/C#/Node.js).
  • Experience building and operating security tooling and monitoring systems.
  • Knowledge of container security and CI/CD security practices.

Responsibilities

  • Own threat detection, SIEM configuration, and incident response across systems.
  • Perform architecture/code/infrastructure reviews and light app pen tests.
  • Maintain and optimize a vulnerability management CI/CD pipeline.
  • Collaborate with engineering to enforce secure coding and remediation practices.
  • Develop and maintain security tooling and training materials for teams.

Skills

Ruby
Java
Python
C#
Node.js
Security monitoring

Tools

Docker
Kubernetes
SAST
DAST
IAST
OWASP

Job description

Engine is the AI-native platform for intelligent travel. For a decade, Engine has built the proprietary technology and supply behind modern business travel, serving over 38,000 customers and nearly 2 million travelers, along with leading travel and AI companies that build on Engine's infrastructure. One system powers business travel, group travel, human agents, and AI agents.

That work has earned recognition as one of Fast Company's Best Workplaces for Innovators (2025), TravelTech's Reservation Platform of the Year (2026), and one of Built In's Best Places to Work (2020-2026).

We're looking for bold, ambitious people to help redefine how businesses manage and experience travel. Working here, you can expect exponential growth, an ambitious pace, full ownership, and high-caliber colleagues who push you to do the best work of your career. Every hire raises the bar.

Come outpace the ordinary and build the future of travel with us.

Engine is seeking a highly-skilled and motivatedStaff Security Engineer to join our team. In this role, you will be a primary owner of the security and integrity of our company's applications and software systems. You will be responsible for building out a vulnerability management pipeline and executing our application security program. You will collaborate closely with engineering teams to ensure that Engine adheres to best practices in application security, tackling complex security repairs and ensuring our "engine" runs fast and securely.

Your Mission:

As part of the Engine team, you'll play a vital role in an environment where innovation meets collaboration. You will drive work independently, syncing regularly to ensure quality and alignment across the following areas:

  • Threat Detection & SIEM Ownership: Own the configuration, tuning, and management of our SIEM solution. You will diagnose unusual threats through sophisticated analysis and develop the alerts needed to respond to security incidents across multiple layers.
  • Security Analysis & Reviews: Perform architecture reviews, code reviews, and infrastructure configuration reviews. You will conduct light penetration testing on web and mobile apps, identifying root causes of vulnerabilities and resolving them using creative problem-solving.
  • Vulnerability Management: Maintain and optimize a vulnerability management CI/CD pipeline within our container/application delivery infrastructure. You will adapt proven methods to align security goals with business objectives, even when guidance is light.
  • Cross-Functional Collaboration: Partner with development and infrastructure teams to enforce secure coding practices and remediation strategies. You will adapt your messaging across teams to reduce misalignment and move security work forward.
  • Implementation & Tooling: Build and maintain the frameworks and tooling for enterprise security, ensuring that security guidelines are clear and actionable for the broader engineering organization.
  • Incident Response: Play a key role in incident response and forensic investigations. You will weigh context and data thoughtfully to make smart decisions during high-pressure situations.
  • Security Advocacy: Stay current on the latest threats and provide direct, clear guidance to development teams. You will help develop security training to empower your peers and improve the team’s overall security posture.
What You'll Bring to Engine:

We're looking for a specialist who is ready to take ownership of team outcomes and deliver high-quality work:

  • Technical Proficiency: Highly skilled in one or more programming languages (e.g., Ruby, Java, Python, C#, Node.js).
  • SIEM & Monitoring: Expertise in managing SIEM solutions with a focus on comprehensive, efficient alerting that reduces "noise."
  • Cloud & Containers: Strong knowledge of Docker and Kubernetes, with hands-on experience in automated container vulnerability management.
  • Security Testing: Mastery of SAST, DAST, and IAST tools, with the ability to perform manual validation testing to confirm findings.
  • Security Principles: Deep knowledge of the OWASP Top 10, Mitre Top 25, and secure coding practices.
  • Analytical Problem Solving: Ability to assess complex, ambiguous situations to identify root causes and provide thoughtful input on difficult security topics.
  • Communication: A track record of earning credibility with peers through clear, direct communication and a passion for mentoring others.
  • Compliance & Frameworks: Experience working with cloud security concepts and compliance frameworks such as
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

VP, Security
VP, Security

Engine • Denver (CO)

Hybrid
USD 298,000 - 400,000
Hybrid-hub model
Equity
Remote-friendly offices
Staff Software Engineer
Staff Software Engineer

Engine • Northern (KY)

Hybrid
USD 200,000 - 245,000
Equity
Hybrid-remote options
Senior Security Engineer
Senior Security Engineer

Foundation Capital • Phoenix (AZ)

On-site
USD 130,000 - 190,000
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Other
Other

Torsap Thai Kitchen • San Francisco (CA)

On-site
USD 140,000 - 190,000
Senior Manager, Information Technology
Senior Manager, Information Technology

Engine • United States

On-site
USD 160,000 - 230,000
Equity
Variable pay
Hybrid work model
Staff Software Engineer
Staff Software Engineer

Engine • Denver (CO)

Hybrid
USD 200,000 - 245,000
Equity included
Hybrid work model
Remote-friendly environment
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Staff Security Engineer
Staff Security Engineer

Topaz Labs • Dallas (TX)

On-site
USD 150,000 - 210,000
100% covered medical/dental/vision
15 days annual PTO
401k matching
Security Engineer
Security Engineer

Factory • San Francisco (CA)

On-site
USD 120,000 - 150,000