openleverjobgether
Senior/Staff Engineer, Application & Product Security
Jobgether
LocationUS
EmploymentFull-time
Posted2026-08-24T12:06:41.811000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:68006bcb-226e-41a3-9c9d-7f9665e51d15
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior/Staff Engineer, Application & Product Security based in the United States. This role will help shape how security is built into products and engineering practices across a rapidly growing technology organization. You will make secure development the default by embedding security requirements, guardrails, threat modeling, and risk management throughout the software development lifecycle. The position combines hands-on application security engineering with close partnership across product, engineering, DevOps, and services teams. You will work directly with source code and complex microservice architectures to identify meaningful risks and design practical solutions. The role also offers the opportunity to influence the security of emerging AI and agent-based capabilities as they move rapidly into production. Success requires balancing strong security outcomes with an understanding of business priorities and developer experience. This is an execution-oriented environment for a security engineer who wants to build scalable security capabilities rather than simply identify vulnerabilities. Champion a secure-by-default culture by embedding defense-in-depth principles into engineering frameworks, architecture, and everyday development practices. Develop security requirements for applications and services and partner directly with engineering teams to incorporate them into the software development lifecycle. Conduct hands-on source-code reviews and investigations to develop a deep understanding of applications, architectures, and potential attack paths. Drive the application and product security roadmap in collaboration with product leadership, engineering, and the broader security organization. Partner closely with product, engineering, DevOps, and services teams to enable secure software delivery without unnecessarily slowing development. Design and implement practical solutions to remediate vulnerabilities, mitigate security risks, and strengthen application defenses. Research relevant threats, attack techniques, and emerging security risks, including those affecting AI and agent-based product capabilities. Conduct security risk assessments, penetration testing, and threat modeling across products and services. Translate security findings into actionable recommendations, secure coding guidance, and educational resources for engineering teams. Build automation, frameworks, and services that eliminate repetitive security work and create scalable security capabilities. Prioritize security initiatives according to business and technical risk rather than relying solely on vulnerability volume or automated tooling output. Collaborate with stakeholders across the organization to continuously improve security processes, architecture, and engineering practices. Requirements: 6+ years of professional experience in application security, product security, or a closely related security engineering discipline. Strong software development skills, with the ability to write production-quality code and automate repetitive security tasks. Experience building security frameworks, services, or automation that address practical application security challenges. Hands-on experience with microservice architectures and modern software development environments. Demonstrated ability to investigate source code and develop a deep technical understanding of complex applications and codebases. Strong knowledge of application security principles, secure software development practices, vulnerability management, threat modeling, and penetration testing. Experience working with security testing and development lifecycle concepts such as SAST, DAST, SBOMs, and related tooling, with the judgment to go beyond tool-generated findings. Ability to prioritize security work based on meaningful risk, business impact, exploitability, and rea
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.