6 дней назад
Sr. Security Engineer (Application Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr. Security Engineer (Application Security/AI): Securing SaaS products through architecture reviews, white-box penetration testing, SSDLC maturity, and CI/CD security automation with an accent on AWS, web application vulnerabilities, and emerging AI attack surfaces. Focus on designing practical risk-based controls, securing agentic systems and LLM-powered workflows, and building security partnerships across engineering, product, legal, and leadership.
Location: Hybrid role based in Salt Lake City, Utah, United States; employees may work remotely, from an office, or through a combination depending on role and team needs.
Company
develops AI-driven work acceleration products, including Lucidchart, Lucidspark, and airfocus, for visual collaboration and organizational transformation.
What you will do
- Conduct security architecture, product design, and feature reviews to identify risks early and recommend practical mitigations.
- Partner with engineering and product teams throughout the software development lifecycle as an application security subject matter expert.
- Mature the Secure Software Development Lifecycle through secure coding standards, security requirements, developer education, and security champions.
- Develop scalable security tooling and automate security controls in CI/CD pipelines with a focus on reducing risk.
- Assess AI tools, agentic systems, MCP, and LLM-powered workflows against emerging security threats.
- Mentor engineers and communicate security risks in practical business terms to technical and leadership stakeholders.
Requirements
- 5+ years of combined experience in software engineering, application security, product security, or a related field in a SaaS environment.
- Experience securing web applications using modern frameworks and cloud-native architectures, particularly AWS.
- White-box penetration testing experience and strong knowledge of OWASP Top 10, API security, authentication, and authorization vulnerabilities.
- Strong understanding of SSDLC principles and experience implementing or maturing secure development programs.
- Experience integrating security tooling into modern CI/CD pipelines and conducting meaningful security architecture reviews.
- Strong written and verbal communication skills, with the ability to build trusted relationships across engineering, product, legal, and leadership teams.
Nice to have
- Development experience with modern technology stacks.
- Knowledge of OWASP ASVS, NIST 800-53, SOC 2, or GDPR.
- Hands-on security certifications such as OSCP, BSCP, GWEB, or PNPT.
- Bug bounty program management experience.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
Culture & Benefits
- Hybrid workplace with remote and office-based work options depending on role and team needs.
- Focus on work-life balance, individual empowerment, initiative, ownership, and teamwork.
- Inclusive environment that values diverse perspectives and respectful collaboration.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Senior Application Security Engineer (AI)
164 300 - 222 300$
10 дней назад
Security Engineer (Application Security)
120 000 - 140 000$
9 дней назад
Senior Application Security Engineer (AI)
160 300 - 240 500$
6 дней назад
Senior Engineer, Security (AWS)
Writer
11 дней назад
Staff Security Engineer, Applications (AI)
204 000 - 240 000$
6 дней назад