Staff Application Security Engineer
CensysRemote (USA)1w ago
Job description
About the role
Censys is on the lookout for a Staff Application Security Engineer who will play a role in embedding security into our software development and deployment workflows. This position is essential for establishing secure engineering practices that empower our teams to develop and launch software efficiently and securely. As we enhance our capabilities in artificial intelligence and machine learning, your contributions will be vital in safeguarding our platform.
Key facts
What you'll do
- Design and enhance the application security and DevSecOps strategy, emphasizing the integration of security measures early in the software development lifecycle through automation and efficient processes.
- Build and oversee DevSecOps tools within Kubernetes and Google Cloud Platform, with a particular focus on securing AI and ML workloads.
- Incorporate security checks into continuous integration and continuous deployment (CI/CD) pipelines, including code analysis, secret management, and dependency scanning, while working closely with engineering teams to ensure integration.
- Develop essential security components such as hardened service templates and secure service catalogs to facilitate secure development practices for engineers.
- Define the security architecture for AI and ML processes, implementing necessary controls for model training, deployment, and inference phases.
- Collaborate with the Corporate Security team on compliance efforts, designing and executing controls to achieve SOC 2 and ISO 27001 readiness.
- Offer technical mentorship and guidance on security best practices, including conducting threat modeling sessions and design reviews.
- Engage in a shared on-call rotation to assist with production system support and incident response activities.
Requirements
- A minimum of 10 years of experience in Security Engineering, DevSecOps, Site Reliability Engineering (SRE), or related domains, with a proven track record of leading security initiatives across teams.
- Extensive knowledge of securing Kubernetes environments, including aspects like container security, network policies, and supply chain security.
- Demonstrated experience with application security tools integrated into CI/CD processes, such as GitHub Actions and ArgoCD.
- Strong grasp of common attacker tactics, techniques, and procedures (TTPs), as well as familiarity with frameworks like MITRE ATT&CK.
- Solid background in cloud services, particularly Google Cloud Platform (GCP), with experience in securing data pipelines and machine learning infrastructure.
- Proficient in Infrastructure-as-Code practices (e.g., Terraform, Crossplane) and security scanning for cloud resources.
- Skilled in scripting and automation using languages such as Python or Bash.
- Capable of contributing effectively to technical discussions and making data-driven decisions.
- Excellent communication abilities and an understanding of developer needs to implement security measures without hindering productivity.
Nice to have
- Experience in establishing or scaling an Application Security (AppSec) or DevSecOps program from the ground up.
- Familiarity with security platforms such as Orca Security or Aikido Security.
- Experience in securing machine learning toolchains (e.g., TensorFlow, PyTorch) and awareness of AI-specific security threats.
- Practical experience with Web Application Firewalls (WAF) and DDoS protection strategies.
- Knowledge of monitoring and observability systems for detecting security anomalies.
- Understanding of AI governance and compliance standards.
- Interest in leveraging AI and large language model (LLM) tools to boost productivity and enhance product features.
Skills & tools
- Kubernetes
- Google Cloud Platform (GCP)
- CI/CD (GitHub Actions, ArgoCD)
- Infrastructure-as-Code (Terraform, Crossplane)
- Scripting (Python, Bash)
- Application Security Tooling (SAST, DAST, SCA, Secret Scanning)
- MITRE ATT&CK
- AI/ML Security
Practical notes
- The salary range for candidates located in high cost of living areas (e.g., San Francisco Bay, New York City, Seattle) is between $198,000 and $233,000 USD.
- For other locations within the US, the salary range is between $172,000 and $216,000 USD.
- Compensation packages include eligibility for bonuses and equity options.
- Benefits encompass health, dental, and vision insurance, retirement plans with company contributions, parental leave, mental health support, flexible paid time off, and a stipend for professional development.
- If hired, in-person onboarding at our headquarters in Ann Arbor is mandatory.
- Candidates are required to have their cameras on during video interviews.
- Censys is committed to being an equal opportunity employer.
- We are not currently working with third-party agencies for this position.