Staff Security Engineer (Application Security)

Writer

United States

Hybrid

USD 170,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Parental leave
Hybrid work
Stock options
401k

Job summary

Writer is seeking a Staff Security Engineer to build scalable security foundations for AI systems powering top brands. You’ll embed security into every line of code, secure LLM architectures, and define threat models across the platform.

The role is hybrid with offices in NYC, SF, and Seattle, reporting to the head of security engineering. You’ll lead security reviews, automate vulnerability detection, and champion secure coding standards company-wide.

Qualifications

  • 4+ years in application security engineering or equivalent
  • 2

Responsibilities

  • Lead threat modeling for AI/ML platforms and secure architectures for new features
  • Establish and maintain SAST/DAST in CI/CD pipelines and perform secure code reviews
  • Develop reusable security patterns and libraries for developers to ship securely
  • Collaborate with product and engineering teams to embed security by design
  • Conduct security assessments and pen tests on applications, services, and APIs

Skills

Security engineering
Threat modeling
SAST/DAST
DevSecOps
Secure coding
Python
Java
Go
JavaScript
TypeScript
CI/CD tooling
Code reviews
Automation
Communication

Tools

SAST tools
DAST tools
Vulnerability management
Security testing frameworks

Job description

  • This is where security meets innovation at enterprise scale
  • As a staff security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands
  • You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy
  • The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform
  • This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely”
  • You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago
  • This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering
  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact
  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers.
  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
Benefits
  • Health: Selection of employer-covered medical plans, plus dental, vision, life insurance, and FSA.
  • Family-friendly: Competitive parental leave policy, working parents can truly own their schedules.
  • Hybrid culture: We’re built around a mix of in office collaboration and remote work when needed.
  • Finance: Company stock options, plus a 401k plan with employer contributions.
  • Growth: Learning and development stipend and generous PTO.
  • SF/NY/London office space: Three beautiful sunny offices in three incredibly exciting cities.

Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implicationsA builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks itExcellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to actionMinimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environmentsKnowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual reviewAlignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers*This role is open to Mid, Sr. and Staff level candidates

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff security engineer, application security
Staff security engineer, application security

WRITER • San Francisco (CA)

Hybrid
USD 183,000 - 240,000
Generous PTO and holidays
Medical, dental, vision coverage
Parental leave (16 weeks)
+3
Staff security engineer, application security
Staff security engineer, application security

Showcify, Inc. • United States

On-site
USD 170,000 - 230,000
Generous PTO
Health coverage
Parental leave
+3
Staff security engineer, application security
Staff security engineer, application security

Writer • California (MO)

Hybrid
USD 180,000 - 240,000
Generous PTO
Medical, dental, vision coverage
Parental leave
Security engineer, application security WRITER Middle 4h ago
Security engineer, application security WRITER Middle 4h ago

Remote Genie • San Francisco (CA), Northern (KY)

On-site
USD 180,000 - 240,000
Health coverage
Parental leave
Fertility support
+4
Staff security engineer, application security
Staff security engineer, application security

Cybersecurity Jobs • Seattle (WA)

Hybrid
USD 183,000 - 240,000
Generous PTO
Medical, dental, and vision coverage
Parental leave 16 weeks
+9
Security engineer, detection and response
Security engineer, detection and response

WRITER • San Francisco (CA)

On-site
USD 165,000 - 230,000
Generous PTO
Medical, dental, and vision coverage
Parental leave
+3
Security engineer, detection and response
Security engineer, detection and response

Cybersecurity Jobs • New York (NY)

On-site
USD 132,000 - 240,000
Generous PTO
Medical/Dental/Vision
Parental leave 16 weeks
+8
Security engineer, detection and response
Security engineer, detection and response

WRITER • New York (NY)

On-site
USD 132,000 - 240,000
Generous PTO
Medical, dental, and vision coverage
Parental leave
+7
Staff Application Security Engineer - AI Platform
Staff Application Security Engineer - AI Platform

Writer • United States

Hybrid
USD 170,000 - 210,000
Health insurance
Parental leave
Hybrid work
+2
Staff Application Security Engineer – AI/ML
Staff Application Security Engineer – AI/ML

WRITER • San Francisco (CA)

Hybrid
USD 183,000 - 240,000
Generous PTO and holidays
Medical, dental, vision coverage
Parental leave (16 weeks)
+3