5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices
Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks
Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it
Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native)
Hands-on experience threat modeling and running security architecture reviews
Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication
Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program
Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
Prior experience building security telemetry pipelines or vulnerability management frameworks
Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability
Familiarity with bug bounty programs and vulnerability disclosure processes
Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location
In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package