Staff Application Security Engineer

September 28, 2026

Job Description

What you’ll do:

  • Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.
  • Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.
  • Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.
  • Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.
  • Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.
  • Evaluate, implement, tune, and operationalize application-security tooling, including:
    • Static application security testing (SAST)
    • Dynamic application security testing (DAST)
    • Software composition analysis (SCA)
    • Secrets detection
    • Infrastructure-as-code security scanning
    • Container and image security scanning
    • API and cloud-native application security controls
  • Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.
  • Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.
  • Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.
  • Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.
  • Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.
  • Mature software supply-chain security practices, including:
    • Machine-readable software bills of materials (SBOMs)
    • Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications
    • Build and release provenance
    • Artifact, package, container-image, and binary signing
    • Artifact verification and trusted promotion processes
    • Secure artifact repositories and package registries
    • Approved dependency sources and package integrity verification
    • SLSA-aligned build integrity, provenance, and release controls
  • Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.
  • Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
  • Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.
  • Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.
  • Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
  • Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.

NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.

Required qualifications:

  • 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related field.
  • Demonstrated experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams.
  • Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.
  • Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices.
  • Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling.
  • Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
  • Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition.
  • Knowledge of common application-security risks, including authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.
  • Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
  • Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.
  • Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable secure-development and supply-chain security frameworks.
  • Ability to read and assess production code and scripts in one or more modern programming languages.
  • Strong written and verbal communication skills, including the ability to explain technical risk and tradeoffs to developers, leaders, auditors, and nontechnical stakeholders.

Preferred qualifications:

  • Experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls.
  • Experience with VEX, CSAF, SBOM formats such as SPDX or CycloneDX, and component or vulnerability intelligence workflows.
  • Experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.
  • Experience with common source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.
  • Experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies.
  • Experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements.
  • Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance product environments.
  • Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.