Staff Application Security Engineer
New
C
CensysCybersecurity
This position is remote within the United States or Canada.Full-TimeStaff
SalaryFor high cost of living areas (San Francisco Bay, New York City, and Seattle), the expected salary range for this position is $198,000 USD – $233,000 USD, plus bonus eligibility and equity. For all other US locations, the expected salary range for this position is $172,000 USD – $216,000 USD, plus bonus eligibility and equity.
Apply NowOpens the employer's application page
Job Details
- Experience
- 10+ years
- Required Skills
- PythonBashGCPKubernetesCI/CDTerraformGitHub Actions
Requirements
- 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles.
- Deep expertise securing Kubernetes environments, including container images and network policies.
- Strong experience with Application Security tooling integrated into CI/CD pipelines like GitHub Actions and ArgoCD.
- Strong understanding of attacker tactics, techniques, and procedures (TTPs) and MITRE ATT&CK.
- Strong grasp of cloud services, specifically GCP security.
- Proficiency with Infrastructure-as-Code (Terraform, Crossplane).
- Proficiency with scripting and automation (Python, Bash).
- Experience leading complex security initiatives across multiple teams.
- Strong communication skills and empathy for developer needs.
- Demonstrated ability to drive data-driven decisions amidst ambiguity.
Responsibilities
- Own and drive the AppSec/DevSecOps program roadmap across engineering, focusing on shift-left practices and automation.
- Design, build, and maintain DevSecOps tooling within Kubernetes and Google Cloud Platform (GCP).
- Lead the integration of security scanning, secret detection, and policy enforcement into CI/CD pipelines.
- Deliver hardened service templates and secure guardrails to reduce developer friction.
- Set security architecture direction for AI/ML workflows, including model training and inference pipelines.
- Partner with CorpSec to implement security controls for SOC 2 and ISO27001 compliance.
- Provide technical leadership, mentorship, and threat modeling guidance across engineering teams.
- Participate in shared on-call rotations for production uptime and security incident response.
View Full Description & ApplyYou'll be redirected to the employer's site