Sr. Application Security Engineer
Job description
About the role
This position focuses on the security architecture of Starlink.com and the supporting internet infrastructure used by millions of customers. You will perform security audits, mentor developers on secure coding practices, and manage the bug bounty program to protect global user data. In this role, you will own the design and execution of security initiatives that span the entire application lifecycle for a critical global service. You will act as a trusted advisor, translating complex security threats into actionable guidance for engineering teams. Your work will directly influence the resilience of the systems that deliver internet access to remote and urban communities worldwide. You will balance architectural oversight with hands-on implementation to ensure security controls are effective and scalable. This position requires a proactive mindset to identify risks before they impact customers or operations. You will be a key contributor to maintaining the trust and safety of the Starlink platform.
Key facts
What you'll do
- Architect security infrastructure for the Starlink mobile application and website, ensuring robust defenses against evolving threats.
- Conduct ongoing security assessments and audits of Starlink internet systems to uncover weaknesses and drive remediation.
- Provide early-stage design feedback to engineering teams to integrate security into development processes from the outset.
- Manage and respond to incoming bug bounty reports, evaluating submissions and guiding researchers through resolution.
- Develop prototypes and design security enhancements for the network to address emerging attack vectors.
- Support the expansion of secure, reliable internet access for global communities by hardening infrastructure in diverse environments.
- Implement secure coding standards and practices across web and mobile development initiatives.
- Collaborate with cross-functional partners to align security objectives with product delivery timelines.
- Leverage threat modeling and risk analysis to prioritize security initiatives and resource allocation.
- Drive the adoption of security tools and workflows that improve visibility and control across the engineering organization.
- Conduct code reviews focused on application security to identify and mitigate potential vulnerabilities.
- Define security metrics and reporting to track the effectiveness of implemented controls and improvements.
- Partner with operations teams to ensure security considerations are addressed in deployment and monitoring strategies.
- Lead incident response efforts related to application layer threats and support post-incident reviews.
Requirements
- Bachelor degree in a STEM field with 5+ years of professional security software development experience, or 7+ years of professional security software development experience without a degree.
- Proficiency in at least one programming language such as Python, C++, Golang, or C#.
- Experience designing and deploying application security solutions for mobile or web platforms.
- Must be a U.S. citizen, lawful permanent resident, refugee, or asylee to meet ITAR export requirements.
- Availability to work extended hours and weekends when necessary to support critical security initiatives.
- Demonstrated ability to work independently and make sound decisions in complex security scenarios.
- Strong understanding of secure software development lifecycle practices and how to apply them in fast-paced environments.
- Capability to manage multiple priorities and deliverables while maintaining attention to detail.
- Willingness to stay current with the latest security threats, techniques, and mitigation strategies.
- Commitment to following established security policies, procedures, and governance frameworks.
- Effective communication skills to articulate risks and recommendations to both technical and non-technical stakeholders.
- Experience working in regulated or high-security environments is considered a strength.
- Willingness to support on-call responsibilities as part of the security response posture.
Nice to have
- Advanced degree in a technical or engineering field.
- Proven history of discovering high-impact vulnerabilities in production environments.
- Experience contributing security improvements to large-scale, complex systems.
- Strong understanding of networking protocols and general network security.
- Ability to adapt to new technologies and manage ambiguous project requirements.
- Familiarity with cloud security architectures and modern DevOps toolchains.
- Knowledge of secure wireless and satellite communications protocols relevant to the Starlink platform.
- Experience with bug bounty programs and responsible disclosure processes.
- Background in threat intelligence and adversarial tactics, techniques, and procedures.
- Experience mentoring engineers on secure design patterns and secure coding practices.
Skills & tools
- Web and mobile penetration testing
- Web and mobile application development
- Production infrastructure defense
Practical notes
Total compensation includes potential long-term incentives like company stock or cash awards, discretionary bonuses, and an Employee Stock Purchase Plan. Benefits include medical, dental, and vision coverage, 401(k), life and disability insurance, paid parental leave, 3 weeks of vacation, and at least 10 paid holidays. Company shuttles provide weekday transport between select Seattle locations and the Redmond office. SpaceX is an Equal Opportunity Employer.