Overview
Application Security Engineer focused on reducing software vulnerabilities (CVEs) across the technology stack.
What you'll do
- Own the vulnerability management lifecycle from discovery and prioritization through remediation, reporting, and measurement.
- Harden base OS images and secure open-source dependencies and the broader software supply chain.
- Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
- Evaluate, adopt, and develop security solutions and tooling, including Google’s Assured OSS.
- Define secure-coding practices and drive engineering adoption via guidance, training, and mentorship.
What you'll need
- 8+ years of experience in application security and vulnerability management.
- Deep understanding of software security vulnerabilities including CVEs, OWASP Top 10, and supply chain risks.
- Experience with SAST, DAST, dependency scanning, and vulnerability management tools (e.g., Snyk, GitHub Dependabot, Trivy, Clair, Burp Suite, OWASP ZAP).
- Hands-on experience with cloud-native security across AWS and GCP, including containers, Kubernetes, and microservices.
- BA/BS in Computer Science, Cybersecurity, or a related field (or equivalent industry experience).
- Ability to lead cross-functional initiatives and drive security adoption across engineering teams.
Details
- Remote role located in the United States.
Read the full description and apply on the company’s own careers page.