Staff Security Engineer, Application Security
You'll help scale and mature the security program by owning key security domains and initiatives end-to-end, working closely with engineering to ensure systems are secure by design. This role is highly hands-on, with opportunities to drive meaningful impact through automation, secure design, and developer enablement. You'll operate with significant autonomy while partnering with senior engineers and security leadership to scale security across the organization.
Responsibilities
- Own vulnerability management, application security, API security, and supply chain security domains.
- Improve security coverage, prioritization, and remediation workflows.
- Integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
- Provide pragmatic security guidance to engineering teams.
- Develop security tooling and automation.
- Implement and tune SAST, SCA, DAST, dependency, and container security tools.
- Use AI and LLMs to improve triage, detection, and review processes.
- Triage and prioritize vulnerabilities using risk-based approaches.
- Define and improve SLAs, metrics, and reporting.
- Conduct threat modeling, design reviews, and security assessments.
- Contribute to incident response and security postmortems.
- Identify and remediate systemic risks.
Requirements
- 7+ years of experience in Application Security, Product Security, or Security Engineering.
- Hands-on experience with threat modeling and secure design.
- Experience with vulnerability management and application security tooling.
- Experience in cloud-native environments such as AWS and GCP.
- Experience integrating security into CI/CD pipelines and developer workflows.
- Ability to write Python, Go, or similar languages for automation and tooling.
- Strong cross-functional collaboration skills.
- Bonus: experience scaling security in a high-growth or late-stage startup.
- Bonus: familiarity with AI-driven security workflows or automation.
- Bonus: API security, data protection, or multi-tenant systems experience.
- Bonus: bug bounty and penetration testing experience.
- Bonus: security certifications such as CISSP.
Benefits
- Annual target bonus of 12%
- 401K plan with company match up to 3.5%
- 23 days paid time off per year
- Seven paid holidays
- 20 additional flex remote days annually
- Five company-wide office-optional weeks
- One annual service day
- Paid parental bonding leave
- Health, vision, and dental coverage
- Life and disability insurance covered 100% by NinjaTrader