Apply

Senior Staff Application Security Engineer

Posted 13 days agoViewed

View full description

💎 Seniority level: Staff, 10+ years

📍 Location: United States

💸 Salary: 181000.0 - 266000.0 USD per year

🔍 Industry: Software Development

🏢 Company: Life360👥 251-500💰 $33,038,258 Post-IPO Equity over 2 years ago🫂 Last layoff about 2 years agoAndroidFamilyAppsMobile AppsMobile

🗣️ Languages: English

⏳ Experience: 10+ years

🪄 Skills: AWSDockerPythonSoftware DevelopmentCloud ComputingCybersecurityKubernetesAPI testingREST APICI/CDDevOpsRisk Management

Requirements:
  • 10+ years of hands-on experience in application security, securing cloud-based and containerized environments.
  • Strong understanding of cybersecurity threats, vulnerabilities, and mitigations, with a proactive approach to embedding security throughout the product lifecycle.
  • Deep expertise in secure design, threat modeling, offensive security, and risk reduction beyond compliance checklists.
  • Experience with modern application stacks, security tooling, and DevSecOps pipelines, with a passion for security automation and pragmatic defenses.
  • Working knowledge of one or more programming languages (preferably Python) and experience writing software that enhances security processes.
  • Exceptional ability to distill complex security concepts into clear actions, driving alignment across engineering teams without direct authority.
  • A collaborative mindset with a strong ability to build relationships, influence cross-functional teams, and lead high-impact security initiatives.
  • Creative and strategic thinker who can holistically reduce risk, scale security through smart design, and bring clarity to ambiguous challenges.
  • A track record of contributions to the security community (research, blogging, presentations, bug bounty) is a plus.
  • Strong bias for action, ownership, and delivering measurable improvements to security posture.
Responsibilities:
  • Drive “shift left” security initiatives, embedding security best practices seamlessly into the software development lifecycle to proactively identify and mitigate risks.
  • Assess third-party vendors and cloud service providers to ensure compliance with security and privacy standards.
  • Participate in the security on-call rotation to respond to and mitigate security incidents.
  • Document security-relevant architectural decisions and ensure security considerations are integrated into system designs.
  • Serve as a trusted advisor, offering web and mobile security expertise to enable engineering and product teams to make informed, confident decisions.
  • Perform technical security assessments and reviews, research, uncover, and reproduce vulnerabilities, design secure protocols and systems, and write tests to drive architecture changes
  • Provide guidance and education to engineering and product teams on available security controls and their appropriate use to help prevent vulnerabilities.
  • Partner closely with product and engineering teams to design solutions that are secure by default
  • Scale security efforts by integrating automation for the identification, prioritization, and remediation of vulnerabilities. Empower engineering teams through automation, security guidance, tooling, patterns, and training to scale security practices across the organization.
Apply

Related Jobs

Apply

📍 Canada, United States, United Kingdom

🧭 Full-Time

💸 150000.0 - 210000.0 CAD per year

🔍 Application Security

🏢 Company: Ping Identity👥 1001-5000💰 $35,000,000 Series F over 10 years ago🫂 Last layoff over 1 year agoGovernmentSecurityIdentity ManagementSoftware

  • 4+ years of proficiency in a mix of Enterprise Application Security, API Security, Web Application Security, and Mobile Application Security
  • 4+ years of developing commercial or open-source products (experience in Java or Javascript preferred) or equivalent experience
  • Exceptional problem-solving skills, curiosity about the inner workings of systems and showing attention to details and documentation
  • Excellent written and oral communication skills
  • Own multiple Security Engineering assignments working with Ping Identity products, processes and tooling
  • Provide technical leadership and mentor other Product Security Engineers
  • Assist in proposing, developing and improving Secure Software Development Lifecycle (SSDLC) practices alongside global, high-performance product engineering teams
  • Work with the product teams to perform architectural, security design/code reviews, vulnerability assessment and management
  • Perform security tasks including (but not limited to) threat modeling, developer training, static code analysis, dynamic runtime fuzzing, building custom tools and automation, and exploit development.
  • Innovate in all aspects of automation of SSDLC tasks including use of Generative AI
  • Assist the presales, support and customer success teams responding to prospect, customer and field questions related to product and industry security
  • Engage with third-party security consultants for independent security assessments, bug bounties and penetration testing of the product

AWSSoftware DevelopmentCybersecurityJavaJavascriptLDAPOAuthCI/CDRESTful APIsLinuxDevOps

Posted about 2 months ago
Apply