Role overview

Senior Application Security Engineer

Requirements and responsibilities

Readable role content extracted into sections for faster review.

Key Responsibilities

  • Security Development Lifecycle (SDLC) Integration: Support security practices throughout the entire software development process, from design review through deployment.
  • Application Security Testing: Perform offensive penetration testing on web applications, internal services, and robot-side software to identify and remediate vulnerabilities.
  • Automation and Tooling: Support security tools, including Static Application Security Testing (SAST) or Dynamic Application Security Testing (DAST) or runtime vulnerability assessments, and Software Bill of Materials (SBOM) systems. Experience with systems such as Artifactory and GitHub Security.
  • Threat Modeling and Security Reviews: Support threat modeling including security reviews of major software releases.
  • Vulnerability Management: Manage the lifecycle of identified vulnerabilities, prioritizing remediation efforts based on risk to the fleet, proprietary code, and cloud infrastructure.
  • Collaboration: Partner with development, platform, and infrastructure teams to ensure security requirements are met without hindering engineering velocity.

Required Qualifications

  • 5+ years of dedicated, hands-on experience in Application Security (AppSec) engineering or a related senior-level security role.
  • Demonstrated expertise in Application Security engineering with programming skills.
  • Experience supporting security controls in CI/CD pipelines and source control systems (e.g., GitHub, GitLab).
  • Experience with penetration testing and vulnerability scanning.
  • Proficiency in at least one modern programming language (e.g., Python, Go, C++).
  • Strong understanding of security best practices for cloud-native, microservice, and distributed systems architecture.
  • Experience with cloud security such as AWS or GCP.
  • Experience mentoring junior security engineers.

Preferred Experience

  • Experience in a rapidly scaling organization (IoT or robotics experience is a plus).
  • Experience with AI for coding (such as Claude Code) or AI for application security protection (such as AI in security tooling) is a plus.

Details

  • 401(k) Plan:Includes a 6% company match.
  • Equity:Company stock options.
  • Insurance Coverage:100% company-paid medical, dental, vision, and short/long-term disability insurance for employees.
  • Benefit Start Date:Eligible for benefits on your first day of employment.
  • Well-Being Support:Employee Assistance Program (EAP).
  • Time Off:Exempt Employees:Flexible, unlimited PTO and 12 company holidays, including a winter shutdown.Non-Exempt Employees:10 vacation days, paid sick leave, and 12 company holidays, including a winter shutdown, annually.
  • Exempt Employees:Flexible, unlimited PTO and 12 company holidays, including a winter shutdown.
  • Non-Exempt Employees:10 vacation days, paid sick leave, and 12 company holidays, including a winter shutdown, annually.
  • On-Site Perks:Catered lunches four times a week and a variety of healthy snacks and refreshments at our Salem and Pittsburgh locations.
  • Parental Leave:Generous paid parental leave programs.
  • Work Environment:A culture that supports flexible work arrangements.
  • Growth Opportunities:Professional development and tuition reimbursement programs.
  • Relocation Assistance:Provided for eligible roles.
  • Annual Discretionary Bonus: Provided for eligible roles.
  • Exempt Employees:Flexible, unlimited PTO and 12 company holidays, including a winter shutdown.
  • Non-Exempt Employees:10 vacation days, paid sick leave, and 12 company holidays, including a winter shutdown, annually.
Similar roles

Keep a backup shortlist.

Browse stack
FocusApplication SecurityRole area
Seniority signalSeniorCandidate level
StackAWS, CI/CD, GCPPrimary skills
Location7 accepted countriesEligibility

Stack

Use these tags to compare similar remote roles.

Location eligibility

Candidates should apply only when their profile country is listed here.

Hiring flow

WithMira shows the role, then sends candidates to the company application.

1Check role fit, stack, and location eligibility in WithMira.
2Open the company application page from the tracked apply link.
3Save the role or subscribe for similar opportunities before leaving.
Apply on company siteCompany siteOpen link