Application Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer: Own and lead the vulnerability management lifecycle for the entire tech stack, securing base OS images, scanning and patching OSS dependencies, and integrating SAST/DAST tools into CI/CD pipelines. Focus on evaluating solutions like Google’s Assured OSS, defining secure coding practices, developing automated security tests, and driving security adoption across engineering teams.
Location: Remote from the US
Salary: $153,000 - $238,000 annually
Company
is the Work AI platform that powers intelligent enterprise search, AI assistants, and scalable AI agents across SaaS connectors and robust APIs.
What you will do
- Own vulnerability management lifecycle, ensuring tech stack is free from known CVEs.
- Implement secure base OS images and harden systems against threats.
- Scan, monitor, and patch OSS dependencies to mitigate supply chain risks.
- Research and recommend open-source security solutions like Google’s Assured OSS.
- Integrate SAST, DAST, and dependency scanning into CI/CD pipelines with engineering teams.
- Define secure coding best practices and develop automated security validation tests.
- Lead adoption of custom security solutions and provide guidance/training to teams.
Requirements
- BA/BS in Computer Science, Cybersecurity, or equivalent (5+ years in application security and vulnerability management).
- Deep knowledge of CVEs, OWASP Top 10, supply chain risks.
- Experience with SAST/DAST tools (Snyk, Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
- Familiarity with package managers (npm, pip, Maven, Go modules) and securing OSS.
- Coding in Go, Python, Java, or C++; cloud-native security in AWS/GCP/Azure.
- Container/Kubernetes security, microservices; lead cross-functional initiatives.
Culture & Benefits
- Fast-paced, collaborative environment with security as shared responsibility.
- Equity, variable compensation, and comprehensive benefits.
- AI-first mindset with focus on enterprise trust and innovation.
- Commitment to diversity, inclusion, and equal opportunity.
- Global team across 25+ countries, powering integrations with Microsoft Teams, Zoom, etc.
Hiring process
- AI-focused exercise or discussion to assess AI integration in role.
- Standard application with privacy notices and arbitration agreement for US applicants.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →