Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment
Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch
Provide practical security architecture guidance to Engineering, Product, and IT teams
Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems
Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs
Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities
Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom
Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities
Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise
Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly
Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment
Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths
Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely
Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI-safety content
Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly
Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity
Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision-making
Owns meaningful AppSec goals over a semi-annual or annual horizon and independently identifies the right solutions to ambiguous, open-ended problems
Drives cross-team collaboration and operational improvements beyond isolated tickets or one-off reviews
Makes informed decisions by balancing technical detail, business context, customer trust, and long-term risk
Sets a high bar for ownership, communication, mentoring, and technical judgment, and helps raise the effectiveness of peers and partner teams
Improve the health and flow of AppSec findings by keeping prioritization, remediation, and verification moving within defined SLAs
Complete recurring application reviews or threat models for important systems and features
Increase engineering adoption of secure patterns, AppSec tooling, and security training
Reduce manual toil and improve AppSec signal quality through targeted automation and responsible use of AI-assisted workflows
Additional benefits for this role may include: equity; company bonus or sales commissions/bonuses; 401(k) plan; at least 10 paid holidays per year, flex PTO, and parental leave; employee assistance program and wellbeing benefits; global travel coverage; life/AD&D/STD/LTD insurance; FSA/HSA and medical, dental, and vision benefits
Tier 1 Pay Range (San Francisco, New York City, Seattle)
Tier 2 Pay Range (All other US Locations)
We are AI Native
Apollo.io is an AI-native company built on a culture of continuous improvement. We’re on the front lines of driving productivity for our customers—and we expect the same mindset from our team
Why You’ll Love Working at Apollo
At Apollo, we’re driven by a shared mission: to help our customers unlock their full revenue potential. That’s why we take extreme ownership of our work, move with focus and urgency, and learn voraciously to stay ahead
We invest deeply in your growth, ensuring you have the resources, support, and autonomy to own your role and make a real impact. Collaboration is at our core—we’re all for one, meaning you’ll have a team across departments ready to help you succeed. We encourage bold ideas and courageous action, giving you the freedom to experiment, take smart risks, and drive big wins
If you’re looking for a place where your work matters, where you can push boundaries, and where your career can thrive—Apollo is the place for you
The listed Pay Range reflects the total cash compensation inclusive of annual base salary and annual bonus as applicable. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonus target and annual base salary for the role. This salary range may be inclusive of several career levels at Apollo and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role who are not located in the US may request the annual salary range for their location during the interview process
$218,000—$273,000 USD
$190,000—$237,000 USD