Staff Security Engineer - Application Security

Colossus Technologies Group

United States

On-site

USD 180,000 - 260,000

Full time

10 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Colossus Technologies Group is seeking a Staff Security Engineer focused on building the next generation of its Application Security program. This role centers on creating security tooling and automation rather than merely running scanners or gatekeeping code reviews.

You will work on AI-powered agents, AI-assisted SAST/DAST, and automated threat modeling to scale security across fast-moving engineering teams. Strong coding skills in Python or Go are essential for production-grade tooling.

Qualifications

  • Experience building AppSec tooling or security product features.
  • Strong coding skills in Python, Go or similar languages.
  • Ability to analyze production code and architecture for vulnerabilities.

Responsibilities

  • Design and build scalable AppSec systems and tooling.
  • Develop AI-powered agents to review architecture and code for vulnerabilities.
  • Advance SAST/DAST capabilities with AI to find gaps in existing tooling.
  • Automate threat modeling and secure design reviews at scale.
  • Integrate security feedback into developers' CI/CD workflows.
  • Research new attack paths and turn findings into repeatable tooling.

Skills

Security engineering
AppSec
Python
Go
Threat modeling
Code review

Tools

Security scanners
Static analysis
Dynamic analysis
CI/CD tooling

Job description

Staff Security Engineer - Application Security

Colossus Technologies Group is working with a high-tech fintech company to hire a Staff Security Engineer focused on building the next generation of its Application Security program.

This isn't a traditional AppSec role centered around running scanners, reviewing findings and acting as a security gate for engineering.

We're looking for a security engineer who builds.

The team is working on engineering problems around:

  • Building AI-powered security agents that can review architecture and code, identify vulnerabilities and help automate security reviews
  • Developing the next generation of SAST and DAST capabilities, combining traditional security analysis with AI to find vulnerabilities that existing tooling misses
  • Building automated systems that can move from vulnerability discovery into validation, prioritization and eventually remediation
  • Creating security tooling that gives developers useful feedback directly inside their existing development and CI/CD workflows
  • Automating threat modeling and secure design reviews so Product Security can scale alongside a fast-moving engineering organization
  • Securing AI and agentic applications against emerging attack paths including prompt injection, tool abuse, excessive permissions, data leakage and unsafe agent behavior
  • Building controls around software supply chain, dependencies and the path from source code through production
  • Performing deep technical security research against applications, APIs and cloud-native systems, then turning what is learned into repeatable tooling and engineering controls

We're interested in engineers who have built things like security scanners, static or dynamic analysis systems, vulnerability research platforms, automated threat-modeling systems, AppSec developer tooling, security agents or other security products.

Strong software engineering ability is important. Python, Go or similar backgrounds are relevant, along with the ability to read and reason about production code across different languages and architectures.

The ideal person has enough offensive and Application Security depth to find difficult vulnerabilities themselves, but would rather solve the problem at scale by building a system that can find the next thousand.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff AppSec Engineer: Build AI-Powered Security Platforms
Staff AppSec Engineer: Build AI-Powered Security Platforms

Colossus Technologies Group • United States

On-site
USD 180,000 - 260,000
Staff Security Engineer – Detection Engineering
Staff Security Engineer – Detection Engineering

Colossus Technologies Group • United States

On-site
USD 170,000 - 210,000
Staff Security Engineer – Platform Security
Staff Security Engineer – Platform Security

Colossus Technologies Group • United States

On-site
USD 180,000 - 260,000
Platform Security Engineer — Cloud, IAM & Automation
Platform Security Engineer — Cloud, IAM & Automation

Colossus Technologies Group • United States

On-site
USD 180,000 - 260,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Product Security Engineer
Product Security Engineer

Stellar IT Solutions LLC • Sunnyvale (CA)

On-site
USD 140,000 - 200,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Senior Application Security Engineer
Senior Application Security Engineer

AgileEngine • United States

Hybrid
USD 120,000 - 180,000
Flextime
Professional growth
Competitive compensation
+2
Security Engineer, Application Security
Security Engineer, Application Security

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Staff Detection Platform Engineer: Cloud-Scale Security
Staff Detection Platform Engineer: Cloud-Scale Security

Colossus Technologies Group • United States

On-site
USD 170,000 - 210,000