Overview
Staff Application Security Engineer responsible for setting application security technical direction, standards, and secure-by-default approaches at scale.
What you'll do
- Define and drive AppSec security standards and secure-by-default solutions as the application security subject matter expert.
- Build security tooling, automation, and security observability to generate meaningful threat-detection signals.
- Lead threat modeling and risk assessments for high-risk features and platform changes.
- Assess and address security risks introduced by agentic development practices and AI-powered product features in production.
- Partner with engineering teams to prioritize and remediate critical threats, define API security standards, and conduct security code reviews.
- Identify systemic security risks and lead complex multi-team remediation efforts end-to-end.
- Serve as the AppSec point of contact for complex cross-domain security problems.
What you'll need
- Software engineering background with hands-on code review experience (Go preferred; Python or Rust also acceptable).
- Ability to level up other engineers via design reviews, mentorship, and documentation.
- Solid grounding in OWASP Top 10, web vulnerabilities (XSS, injection, access control, cryptography), SAST, and DAST.
- Working knowledge of API security including authentication flows, authorization patterns, and input validation.
- Track record of leading threat modeling on complex, multi-team systems and converting outcomes into architectural decisions.
- Experience implementing secure-by-default frameworks and integrating security into core platforms with product and engineering teams.
- Familiarity with software supply chain security including dependency management, artifact integrity, and build pipeline trust.
Details
- Location: Boston, Massachusetts, USA; and multiple US states listed with remote work options (Connecticut, Delaware, District of Columbia, Maryland, New Jersey, New York, Rhode Island).
- Hybrid work noted: “#LI-Hybrid”.
Read the full description and apply on the company’s own careers page.