Application Security Engineer
Job description
About the role
The role focuses on application and product security for a security-critical product. The security engineer owns the secure SDLC, writes production code, and partners closely with infrastructure and platform teams. This position operates within a security company where access control is the core product. In this capacity, you will drive security outcomes by designing and implementing controls that directly reduce risk across the product surface. You will translate complex threat landscapes into concrete requirements and safeguards that are baked into the architecture. The work demands rigor, curiosity, and a commitment to evidence-based decisions that withstand adversarial scrutiny. You will act as a force multiplier, raising the security baseline for engineers by making secure choices the easiest and default choices.
Key facts
What you'll do
Ownership of the secure SDLC is established by threat modeling, design reviews, and code reviews to set security standards. You will coordinate app pentests internally, drive findings toward closure, and reduce risk across the attack surface. SAST, DSAST, and SCA tooling is built and owned within CI/CD pipelines so security is integrated during development. You will triage vulnerabilities from bug bounties, internal scans, and other sources, then remediate them across multiple attack vectors. Security-critical software is built and maintained through encryption services, authorization enforcement, authentication flows, and shared libraries that make secure development the default choice. The Auth0 and Opal integration is owned end to end, covering tokens, sessions, MFA, and SSO protocols such as SAML, OIDC, and OAuth 2.0. Production Go and TypeScript code is shipped to harden APIs, enforce least privilege, and close vulnerability classes for the long term. Incident response is led by the security engineer on the front lines, containing incidents, identifying root causes, and implementing fixes in collaboration with infrastructure. Cloud security is strengthened through partnership on AWS IAM, EKS, KMS, and network segmentation to reduce exposure. Detection rules and logging, alerting, and response capabilities are leveled up to improve visibility and response times. Security culture is strengthened by mentoring engineers on secure coding, common vulnerability patterns, and security architecture to raise the org's capability. The security roadmap is informed by real product risk, allowing the team to prioritize work that addresses the most critical scenarios. Collaboration is emphasized so that security is viewed as an enabler rather than a bottleneck by engineers and stakeholders. You will communicate security posture to technical and non-technical audiences, aligning on risk acceptance and mitigation strategies.
Requirements
You must have 4+ years of application security or software security engineering experience in previous roles. You must write production code, not only produce findings reports, demonstrating hands-on implementation skills. You must know OAuth 2.0, OIDC, SAML, session management, and token lifecycle details to design and review authentication systems. You must be comfortable working in AWS environments and with containerized technologies such as Kubernetes and Docker. Experience with Go and TypeScript is required to contribute effectively to the codebase. You must have led complex, cross-functional security initiatives from kickoff through completion and delivery. You must have run or participated in external penetration tests and followed findings through to remediation. You must hold a degree as evidence of foundational knowledge and structured learning. You must be able to work full-time in San Francisco and engage closely with the Platform and Infrastructure Engineering teams. You must be available to respond to incidents in a timely manner as part of the on-call security posture.
Nice to have
Only items preferred by the source are listed, and no additions are made here.
Practical notes
The role is based in San Francisco and operates as a full-time position on the Platform team. The security engineer will work closely with Infrastructure Engineering and must be available to respond to incidents.