Staff Application Security Engineer
CensysRemote (USA)2d ago
SecurityEngineeringremotecurated-jd
Job description
Staff Application Security Engineer at Censys
About the role
Censys is seeking a Staff Application Security Engineer to integrate security deeply into our software development and deployment processes. You will define and implement the secure engineering practices that enable our teams to build and release software with confidence and speed. This role is crucial for ensuring the security of our platform, especially as we expand our AI/ML capabilities.
Key facts
What you'll do
- Develop and advance the application security and DevSecOps strategy, focusing on embedding security early in the development lifecycle through automation and streamlined workflows.
- Construct and manage DevSecOps tools within Kubernetes and Google Cloud Platform, with specific attention to securing AI/ML workloads.
- Integrate security checks into CI/CD pipelines, including code analysis, secret management, and dependency scanning, collaborating with engineering teams for smooth adoption.
- Create foundational security elements like hardened service templates and secure service catalogs to simplify secure development for engineers.
- Establish security architecture for AI/ML processes, implementing controls for model training, deployment, and inference.
- Collaborate with Corporate Security on compliance initiatives, designing and implementing controls for SOC 2 and ISO 27001 readiness.
- Provide technical guidance and mentorship on security best practices, including threat modeling and design reviews.
- Participate in a shared on-call rotation to support production systems and incident response.
Requirements
- 10+ years of experience in Security Engineering, DevSecOps, SRE, or similar fields, with a history of leading cross-team security initiatives.
- Extensive experience securing Kubernetes environments, including container security, network policies, and supply chain security.
- Proven experience with application security tools integrated into CI/CD, such as GitHub Actions and ArgoCD.
- Strong understanding of common attacker tactics, techniques, and procedures (TTPs) and frameworks like MITRE ATT&CK.
- Solid experience with cloud services, particularly Google Cloud Platform (GCP), and securing data pipelines and ML infrastructure.
- Proficiency in Infrastructure-as-Code (e.g., Terraform, Crossplane) and security scanning for cloud resources.
- Skill in scripting and automation using languages like Python or Bash.
- Ability to contribute effectively to technical discussions and drive data-informed decisions.
- Excellent communication skills and an understanding of developer needs to implement security without causing friction.
Nice to have
- Experience building or scaling an AppSec or DevSecOps program from its initial stages.
- Familiarity with security platforms like Orca Security or Aikido Security.
- Experience securing ML toolchains (e.g., TensorFlow, PyTorch) and understanding AI-specific threats.
- Hands-on experience with Web Application Firewalls (WAF) and DDoS protection.
- Familiarity with monitoring and observability systems for security anomaly detection.
- Knowledge of AI governance and compliance standards.
- Interest in using AI and LLM tools to enhance productivity and product capabilities.
Skills & tools
- Kubernetes
- Google Cloud Platform (GCP)
- CI/CD (GitHub Actions, ArgoCD)
- Infrastructure-as-Code (Terraform, Crossplane)
- Scripting (Python, Bash)
- Application Security Tooling (SAST, DAST, SCA, Secret Scanning)
- MITRE ATT&CK
- AI/ML Security
Practical notes
- Salary range for high cost of living areas (San Francisco Bay, New York City, Seattle): $198,000 - $233,000 USD.
- Salary range for other US locations: $172,000 - $216,000 USD.
- Compensation includes bonus eligibility and equity.
- Benefits include health, dental, vision, retirement with company contribution, parental leave, mental health support, flexible PTO, and professional development stipend.
- In-person onboarding at HQ in Ann Arbor is required if hired.
- Cameras must be on during video interviews.
- Censys is an equal opportunity employer.
- Not currently engaging with third-party agencies for this role.