Staff Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Application Security Engineer (Cybersecurity): Setting technical direction and defining frameworks for application security at scale with an accent on AI-powered systems and secure-by-default solutions. Focus on building security tooling, leading threat modeling for high-risk features, and remediating systemic security risks across the organization.
Location: Hybrid in Boston, MA or New York, NY, USA
Salary: $234,000 — $300,000 USD
Company
Cloud monitoring and security platform providing observability for logs, dashboards, and APM.
What you will do
- Define security standards and secure-by-default solutions, serving as the Application Security subject matter expert.
- Build scalable security tooling and automation to support threat detection with actionable signals.
- Lead threat modeling and risk assessments for high-risk features and platform changes.
- Assess and address security risks introduced by agentic development and AI-powered product features.
- Partner with engineering teams to remediate critical threats and define API security standards.
- Identify systemic security risks and lead complex, multi-team remediation efforts end-to-end.
Requirements
- Software engineering background with hands-on experience in Go (preferred), Python, or Rust.
- Solid grounding in OWASP Top 10, web vulnerabilities, SAST, and DAST.
- Working knowledge of API security, including authentication flows and authorization patterns.
- Track record of leading threat modeling on complex systems and translating outcomes into architecture.
- Ability to communicate complex business risks and tradeoffs to executive audiences.
- Must be based in or be able to work from Boston or New York, USA
Culture & Benefits
- Equity package including new hire RSUs and Employee Stock Purchase Plan (ESPP).
- Comprehensive healthcare, dental, and global mental health benefits for employees and dependents.
- 401(k) plan with company match.
- Continuous professional development, product training, and structured career pathing.
- Inclusive culture with Community Guilds and an intradepartmental mentor/buddy program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →