Staff Application & Product Security Engineer
New
J
JobgetherProduct security
Based in United StatesFull-TimeStaff
Salary$160,000–$180,000 base compensation plus bonus opportunity.
Apply NowOpens the employer's application page
Job Details
- Experience
- 6+ years of experience in application security, product security, or secure software engineering
- Required Skills
- JavaCI/CDGitHub
Requirements
- Have 6+ years of experience in application security, product security, or secure software engineering.
- Have experience building or maturing an AppSec program across multiple engineering teams.
- Bring strong software development capabilities in an object-oriented programming language; Java is preferred, with the ability to read, debug, and write production-quality code.
- Understand modern application attack surfaces, including authentication, authorization, API security, business-logic vulnerabilities, and contemporary service architectures.
- Have hands-on experience integrating and tuning SAST, SCA, and secrets scanning within GitHub and CI/CD pipelines.
- Be able to reproduce exploits against running applications, validate patches, and turn findings into actionable guidance.
- Have experience coordinating vulnerability disclosure with external researchers and customers, including disclosure timelines and CVE publication.
- Have experience securing shipped software, including secure defaults, hardening guidance, customer advisories, security release notes, and responses to customer scan reports or security RFIs.
- Have practical experience with threat modeling, architecture and design reviews, manual security testing, and developer remediation collaboration.
- Communicate technical risks clearly to developers and executives, and be able to make and defend release-gating security decisions.
- Preferred or beneficial experience includes AI application security; SBOM, VEX, artifact signing, or SLSA; AWS, Kubernetes/EKS, Terraform, or Jenkins; and tools such as Snyk, GitHub Advanced Security, Semgrep, and Burp Suite.
Responsibilities
- Own and mature the secure software development lifecycle, including security requirements, threat modeling, design reviews, and controls for high-risk product changes, APIs, and integrations.
- Run and optimize SAST, SCA, secrets detection, container, and infrastructure-as-code scanning across development and CI/CD environments.
- Build reusable secure patterns, reference implementations, and policy-as-code controls, and lead developer security enablement through training, remediation guidance, and self-service capabilities.
- Manage application and product vulnerabilities through risk-based triage, remediation SLAs, exploit reproduction, patch validation, and release verification.
- Own the penetration testing program and Vulnerability Disclosure Program, coordinating external engagements, researcher and customer communications, remediation, and retesting.
- Coordinate the CVE lifecycle and support product-security incident response activities.
- Maintain application and product-security controls within the NIST CSF 2.0 program and produce audit evidence.
- Own product security across SaaS and customer-hosted environments, and partner with Product Management, Technology leadership, and Architecture on the Product Security Roadmap.
- Review customer security reports and requests, and prepare security advisories, release notes, and hardening documentation.
- Lead security reviews for LLM-enabled features, AI agents, and AI-assisted development workflows, applying relevant OWASP and NIST guidance.
View Full Description & ApplyYou'll be redirected to the employer's site