Sr. Security Engineer
RemoteUnited States
Job Summary
Lead application security reviews, threat modeling sessions, and secure code reviews for new features and significant product changes. Operate and continuously improve SAST, DAST, and SCA tooling while triaging findings with engineering teams to harden the codebase. Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and coordinate third-party assessments. Own the vulnerability management lifecycle from discovery through remediation validation and integrate security tooling into CI/CD pipelines to champion shift-left practices. Investigate security incidents and bug bounty submissions, providing root cause analysis and remediation recommendations. Partner with Product and Engineering on security architecture decisions and develop secure coding standards and training materials. Stay current on emerging threats and CVEs to support continuous program improvement. Report directly to the CISO as an individual contributor helping shape the security program.
Required Qualifications
- 5+ years of experience in application security, with hands-on proficiency in both secure development lifecycle practices and offensive testing
- Strong understanding of web application and API security fundamentals (OWASP, MITRE, CIS, API-specific attack surfaces)
- Experience operating SAST/DAST/SCA ASPM tools
- Fluency in scripting or development languages (Python, JavaScript, Go, Ruby, or similar) sufficient to review code and write internal tooling
- Experience designing and executing penetration tests against modern web and mobile applications
- Familiarity with cloud security (AWS preferred, some GCP and OVH) and container/Kubernetes security
- Comfortable in a regulated environment (e.g., SOC 2 or similar)
- Excellent written and verbal communication skills; able to translate technical risk to non-technical stakeholders
- Proven experience with leveraging AI tools in both professional and personal settings
- You must have the authorization to work in the US to become an employee
Desired Qualifications
- Relevant certifications a plus: OSCP, GWAPT, GPEN, CEH, or equivalent
- Familiarity with cloud security (AWS preferred, some GCP and OVH) and container/Kubernetes security
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.