Application Security Engineer – Staff 2
Primary Locations – Hybrid: 3 days in office in either Atlanta, GA or Mountain View, CA. Fully remote individuals within the United States may be considered if they meet all qualifications.
What is the opportunity?
This senior, hands‑on technical leadership role on our Product Security team focuses on setting the technical direction for how we secure software across Omnissa’s product portfolio. No direct people management; impact through expertise and influence.
Key Responsibilities
- Set technical direction for application security across the portfolio – defining standards, patterns, and guardrails adopted by engineering teams at scale.
- Lead threat modeling for distributed, cloud‑native, and mobile architectures as a repeatable practice embedded in the development lifecycle.
- Define security architecture reference designs that reduce the need for per‑feature security reviews.
- Identify architectural risk early and influence roadmap and design decisions before implementation begins.
- Perform manual code review and application security testing across Java and C++ codebases; codify findings into reusable guidance.
- Scale code review coverage using AI‑assisted analysis and custom CodeQL queries tuned to Omnissa's codebase.
- Conduct variant analysis to ensure confirmed vulnerability classes are remediated consistently across the codebase.
- Triage and validate externally reported vulnerabilities – assess exploitability, severity, business impact, and drive remediation to closure.
- Translate findings into systemic recommendations addressing root‑cause design or implementation gaps.
- Define and evolve the SDL – identify gaps, drive measurable improvements, and own the iteration cycle.
- Improve the feature security review program so that security work shifts left into design and scales across teams.
- Mature the product penetration testing program – define scope, methodology, and cadence; ensure findings drive systemic fixes.
- Build and scale the security champions program; mentor engineers and create training that extends security capability beyond the security team.
- Establish metrics that make program effectiveness visible to engineering and product leadership.
What Success Looks Like
- First 3 months: Build deep understanding of product architecture, development toolchain, and release process; influence in‑flight architectural decisions; identify highest‑leverage gaps.
- First 6 months: Own the security strategy for a significant portfolio area; steer cross‑team prioritization and backlog decisions; iterate improvements on the SDL.
- 12 months and beyond: Deliver measurable, organization‑level improvements in security posture – e.g., reduced mean time to remediation, broadened threat model coverage, new automation adopted across teams; become go‑to technical authority.
Leadership And Team Culture
- Report to the Director of Product Security; take technical direction from the Manager of Application Security, with high degree of autonomy.
- Collaborate with security engineers, product managers and developers focused on innovation and delivery.
- Build trust among team members and stakeholders; commit to customer success.
- Operate in a transparent, communicative environment that emphasizes work‑life balance and enjoyment of work.
- Identify and drive improvements to security processes – internal workflows and partner‑facing interfaces – to reduce friction for development teams and increase daily effectiveness.
What will you bring to Omnissa?
Required
- 12+ years of hands‑on application security experience with demonstrated technical depth and influence.
- Deep knowledge of application security vulnerabilities and mitigation techniques, and judgment to prioritize them by real business and customer impact.
- Proven ability to lead threat modeling, secure design, and security architecture for complex distributed and cloud‑native systems.
- Proficiency in Java or C++, with ability to read, reason about, and review production code.
- Security breadth across application, system, cloud, and mobile domains.
- History of driving technical change and raising the security bar across teams, and mentoring senior engineers.
- Excellent documentation and communication skills, including influencing engineering and product leadership.
- Self‑starter who is adaptable, works independently, and brings clarity to ambiguous problems.
- Pragmatic mindset; able to identify practical short‑term and long‑term strategic solutions.
Preferred
- Experience testing agentic AI systems, and leveraging AI tooling across security testing, triage, and documentation workflows.
- Experience building automation solutions that improve security processes at scale.
- Prior experience as a pen tester for a multi‑tenant SaaS provider.
Location
Atlanta, GA (Primary consideration) or Mountain View, CA.
Location Type
HYBRID – 3 days per week in our Atlanta (or Mountain View) office; remaining days remote. Candidates must reside within a reasonable commuting distance.
Travel Expectations
Travel to remote offices twice per year.
Education
Bachelor’s degree in Computer Science or a related field preferred, or equivalent combination of education and relevant professional experience.
Compensation & Benefits
The typical base salary for this role is between USD $220,000 – $270,000 per year and may be eligible for participation in a corporate bonus program. Actual compensation may vary based on location, experience, education, skill level, or other factors. Omnissa offers a variety of benefits including employee ownership, health insurance, 401(k) with matching contributions, disability insurance, paid‑time off, growth opportunities, and more.
Omnissa is an Equal Employment Opportunity company and Prohibits Discrimination and Harassment of Any Kind: Omnissa is committed to the principle of equal employment opportunity and to providing a work environment free of discrimination and harassment. All employment decisions at Omnissa are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, ancestry, ethnicity, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past, present, or prospective service in the uniformed services, family medical history or genetic information, family or parental status, veteran status, or any other status protected by applicable laws or regulations in the locations where we operate. Omnissa will not tolerate discrimination or harassment based on any of these characteristics. Omnissa welcomes applicants of all ages. Omnissa will provide reasonable accommodations to applicants and employees who have protected disabilities consistent with applicable federal, state and local law.
This job requisition is not eligible for employment‑based immigration sponsorship by Omnissa.