Application Security Engineer – Staff 2
Primary Locations: Hybrid – 3 days in office in either Atlanta, GA or Mountain View, CA. Remote candidates in the United States may also be considered if they meet all qualifications.
What is the opportunity?
This is a senior, hands‑on technical leadership role on our Product Security team. As a Staff 2 Application Security Engineer, you will set the technical direction for how we secure software across Omnissa’s product portfolio—Unified Endpoint Management, Virtual Apps and Desktops, and our cloud‑native and mobile platforms. You will influence architecture and engineering decisions across multiple teams, raise the security bar for the broader organization, and tackle the hardest, most ambiguous problems.
Key Responsibilities
Security Architecture & Threat Modeling
- Set technical direction for application security across the portfolio—defining standards, patterns, and guardrails adopted by engineering teams at scale.
- Lead threat modeling across distributed, cloud‑native, and mobile architectures as a repeatable practice embedded in the development lifecycle.
- Define security architecture reference designs that remove the need for security‑review of each feature.
- Identify architectural risk early and influence roadmap and design decisions before implementation begins.
Secure Code Review & Vulnerability Research
- Perform manual code review and application security testing across Java and C++ codebases; codify findings into reusable guidance for engineers.
- Scale code review coverage using AI‑assisted analysis and custom CodeQL queries tuned to Omnissa’s codebase.
- Conduct variant analysis to ensure vulnerability classes are remediated consistently across the codebase.
- Triage and validate externally reported vulnerabilities—assess exploitability, severity, and business impact, and drive remediation to closure.
- Translate individual findings into systemic recommendations that address root‑cause gaps across products.
Security Program Maturity
- Define and evolve the SDL—identify gaps, drive measurable improvements, and own the iteration cycle.
- Improve the feature security review program so that security work shifts left into design and scales across teams.
- Mature the product penetration testing program—define scope, methodology, and cadence; ensure findings drive systemic fixes.
- Build and scale the security champions program; mentor engineers and create training that extends security capability beyond the security team.
- Establish metrics that make program effectiveness visible to engineering and product leadership.
What Success Looks Like
- First 3 months: Build a deep understanding of the product architecture, development toolchain, and release process; influence early architectural decisions; identify highest‑leverage gaps in the current security program.
- First 6 months: Own the security strategy for a significant area of the portfolio; set direction for engineers; drive cross‑team prioritization, shape backlog and roadmap; iterate improvements on the SDL.
- 12 months and beyond: Deliver measurable, organization‑level improvements in security posture; be recognized as a go‑to technical authority on application security.
Leadership and Team Culture
- Report to the Director of Product Security; take technical direction from the Manager of Application Security.
- Work closely with a committed team of security engineers, product managers, and developers focused on innovation and outcomes.
- Build trust among team members and stakeholders, committing to customer success.
- Operate in a transparent, communicative environment that emphasizes work‑life balance.
- Identify and drive improvements to security processes that reduce friction for development teams and increase effectiveness.
What you will bring
Required
- 12+ years of hands‑on application security experience, with demonstrated technical depth and influence beyond your own work.
- Deep knowledge of application security vulnerabilities and mitigation techniques, and the judgment to prioritize them by real business and customer impact.
- Proven ability to lead threat modeling, secure design, and security architecture for complex distributed and cloud‑native systems.
- Proficiency in Java or C++, with the ability to read, reason about, and review production code.
- Security breadth across multiple domains—application, system, cloud, and mobile.
- A history of driving technical change and raising the security bar across teams, and mentoring senior engineers.
- Excellent documentation and communication skills, including the ability to influence engineering and product leadership.
- Self‑starter who is adaptable, works independently, and brings clarity to ambiguous problems.
- A pragmatic mindset; able to identify practical short‑term and long‑term strategic solutions.
Preferred
- Experience testing agentic AI systems, and ability to leverage AI tooling across security testing, triage, and documentation workflows.
- Experience building automation solutions that improve the security process at scale.
- Prior experience as a pen tester for a multi‑tenant SaaS provider.
Location
Atlanta, GA (primary consideration) or Mountain View, CA. Hybrid – 3 days per week in the office; remaining days remote. Candidates must reside within a reasonable commuting distance.
Travel Expectations
Travel to remote offices twice per year.
Education
Bachelor’s degree in Computer Science or a related field preferred, or equivalent combination of education and relevant professional experience.
Compensation & Benefits
The typical base salary for this role is USD $220,000 – $270,000 per year and may be eligible for corporate bonus program. Omnissa offers competitive compensation and benefits including employee ownership, health insurance, 401(k) with matching contributions, disability insurance, paid‑time off, growth opportunities, and more.
Equal Opportunity Employment
Omnissa is an Equal Employment Opportunity company and prohibits discrimination and harassment of any kind. All employment decisions are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, ancestry, ethnicity, national origin, sex, age, disability, HIV status, sexual orientation, gender identity, marital status, veteran status, or any other status protected by applicable laws or regulations. Omnissa welcomes applicants of all ages and will provide reasonable accommodations for protected disabilities. This job requisition is not eligible for employment‑based immigration sponsorship by Omnissa.