Staff Security Engineer, Application Security

Jobtailor

California (MO)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced security engineer to own and advance key security domains across the product lifecycle.

You will partner with engineering teams to embed security into design reviews, threat modeling, and CI/CD pipelines, while driving vulnerability management and secure automation initiatives.

Qualifications

  • 7+ years of experience in Application Security, Product Security, or Security Engineering.
  • Strong hands-on experience with threat modeling and secure design.
  • Experience with vulnerability management and application security tooling.
  • Experience working in cloud-native environments such as AWS and GCP.
  • Experience integrating security into CI/CD pipelines and developer workflows.
  • Ability to write code in Python, Go, or similar languages for automation and tooling.
  • Strong ability to work cross-functionally with engineering teams.

Responsibilities

  • Own key security domains such as vulnerability management, application security, API security, and supply chain security.
  • Drive improvements in security coverage, prioritization, and remediation workflows.
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
  • Provide actionable, pragmatic guidance that helps teams ship securely.
  • Develop and improve security tooling and automation to reduce manual effort.
  • Implement and tune tools for SAST, SCA, DAST, dependency security, and container security.
  • Leverage AI/LLMs where appropriate to improve triage, detection, and review processes.
  • Triage and prioritize vulnerabilities using risk-based approaches.
  • Partner with teams to ensure timely remediation of critical issues.
  • Help define and improve SLAs, metrics, and reporting.
  • Conduct threat modeling, design reviews, and security assessments.
  • Contribute to incident response and postmortems for security events.
  • Identify and help remediate systemic risks.

Skills

Vulnerability Management
Application Security Tooling
Threat Modeling
Secure Design
Automation in Python
Automation in Go
Security Assessments
Incident Response
Risk-Based Approaches
Security Metrics

Tools

AWS
GCP

Job description

Responsibilities
  • Own key security domains such as vulnerability management, application security, API security, and supply chain security
  • Drive improvements in security coverage, prioritization, and remediation workflows
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows
  • Provide actionable, pragmatic guidance that helps teams ship securely
  • Develop and improve security tooling and automation to reduce manual effort
  • Implement and tune tools for SAST, SCA, DAST, dependency security, and container security
  • Leverage AI/LLMs where appropriate to improve triage, detection, and review processes
  • Triage and prioritize vulnerabilities using risk‑based approaches
  • Partner with teams to ensure timely remediation of critical issues
  • Help define and improve SLAs, metrics, and reporting
  • Conduct threat modeling, design reviews, and security assessments
  • Contribute to incident response and postmortems for security events
  • Identify and help remediate systemic risks
Requirements
  • 7+ years of experience in Application Security, Product Security, or Security Engineering
  • Strong hands‑on experience with threat modeling and secure design
  • Experience with vulnerability management and application security tooling
  • Experience working in cloud‑native environments such as AWS and GCP
  • Experience integrating security into CI/CD pipelines and developer workflows
  • Ability to write code in Python, Go, or similar languages for automation and tooling
  • Strong ability to work cross‑functionally with engineering teams
Hard Skills
  • Vulnerability Management
  • Application Security Tooling
  • Threat Modeling
  • Secure Design
  • Automation in Python
  • Automation in Go
  • Security Assessments
  • Incident Response
  • Risk‑Based Approaches
  • Security Metrics
Soft Skills
  • Cross‑Functional Collaboration
  • Pragmatic Guidance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer (Product Security and Architecture)
Staff Security Engineer (Product Security and Architecture)

Compass • Ventura (CA)

On-site
USD 150,000 - 230,000
Senior Application Security Engineer – Vulnerability Operations
Senior Application Security Engineer – Vulnerability Operations

Veriipro • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Application Security (AppSec) Engineer/Architect
Application Security (AppSec) Engineer/Architect

TechDigital Group • Maryland Heights (MO)

On-site
USD 120,000 - 160,000
Senior Security Engineer – VC Backed Startups
Senior Security Engineer – VC Backed Startups

Jobtailor • United States

On-site
USD 140,000 - 190,000
Staff Software Engineer, Product Security
Staff Software Engineer, Product Security

Jobtailor • California (MO)

On-site
USD 180,000 - 260,000
Senior Security Engineer – Software Engineer
Senior Security Engineer – Software Engineer

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000
Senior Software Engineer, Cloud Security
Senior Software Engineer, Cloud Security

Jobtailor • Boston (MA)

On-site
USD 150,000 - 210,000