Application Security
Application Security Engineer
Shift-left security for product teams — threat models, secure code review, and CI gates that developers actually use.
- Type
- Full-time
- Location
- Remote
- Posted
- 2026-09-20
Responsibilities
- Threat-model features and review PRs for high-risk changes
- Own SAST/DAST/dependency tooling and triage noise
- Partner with eng on authn/authz, secrets, and supply chain
- Teach short AppSec clinics for the street community
Requirements
- Strong web app security fundamentals (OWASP ASVS mindset)
- Can read code in at least one of: TypeScript, Python, Go, Java
- Experience integrating security checks into CI/CD
Nice to have
- Prior pentest or bug bounty background
- IaC / cloud security familiarity