Staff Application Security Engineer
Jobgether United States · $165K–$266K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
Lead the strategy, operation, and continuous improvement of vulnerability management and application security programs. Partner with engineering teams to drive remediation through technical guidance and scalable automation.
What they look for
Requirements
Requires 10+ years of experience in cloud or security engineering with hands-on vulnerability management expertise. Proficiency in Go, Python, JavaScript, and modern cloud security tools is essential.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Offensive Security Engineer based in United States.
This is a high-impact security engineering role focused on strengthening application security and vulnerability management across a complex, multi-surface technology environment. You will help define the technical strategy, architecture, and operating model for security programs spanning cloud services, IoT and firmware, and corporate systems. The role combines deep technical execution with broad influence, requiring you to work directly with engineering teams to identify, prioritize, and remediate critical vulnerabilities. You will build scalable automation, tooling, and security workflows that improve detection, response, and remediation efficiency. You will also translate security risks and technical trade-offs into clear recommendations for engineering leadership and other stakeholders. As a Staff-level technical leader, you will mentor engineers, establish best practices, and provide direction across evolving security priorities. This opportunity is well suited to an experienced security professional who thrives in complex environments and enjoys turning security strategy into measurable outcomes.
\n
Accountabilities
- Lead the strategy, operation, and continuous improvement of vulnerability management and other core application security programs.
- Define what effective security processes should look like, rather than simply executing established procedures.
- Drive reductions in mean time to remediate across the vulnerability backlog as remediation service-level expectations become more stringent.
- Build and champion scalable automation and security tooling for vulnerability detection and response across cloud environments, firmware and Internet of Things systems, and corporate infrastructure.
- Set technical and architectural direction for security programs and translate strategic priorities into actionable execution plans.
- Partner with engineering teams to drive remediation through trusted relationships, clear technical guidance, and practical security recommendations.
- Establish scalable approaches that reduce dependence on manual, one-by-one vulnerability reviews.
- Mentor and develop security engineers while serving as a technical authority on secure design, vulnerability remediation, and application security practices.
- Communicate security risks, remediation priorities, and technical trade-offs to engineering leadership in concise, actionable terms.
- Participate in investigations involving significant or high-profile vulnerabilities and assess their potential impact on infrastructure and applications.
- Participate in an on-call rotation supporting critical vulnerability response and security incidents.
- Evaluate and implement automation and artificial intelligence capabilities that improve triage, detection logic, remediation workflows, reporting, and security decision-making.
- Continuously improve security programs across a broad technology footprint while adapting to changing threats, systems, and organizational priorities.
- Promote strong security practices, collaboration, ownership, and continuous learning across engineering and security teams.
Requirements
- 10+ years of relevant experience as a cloud engineer, security engineer, or in a closely related technical discipline, including substantial hands-on vulnerability management experience across broad, multi-product enterprise environments.
- Strong proficiency in Go, Python, and JavaScript.
- Demonstrated ability to independently establish technical and architectural direction for security programs and influence remediation across teams without direct management authority.
- Significant experience with modern vulnerability management and application security tooling, such as Wiz and Semgrep.
- Deep familiarity with vulnerability assessment and prioritization frameworks, including Common Vulnerability Scoring System (CVSS) and Exploit Prediction Scoring System (EPSS).
- Strong experience with Amazon Web Services (AWS) and modern cloud environments.
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Hands-on experience using artificial intelligence and large language model tools within security workflows, including vulnerability triage, detection logic, and remediation drafting.
- Ability to articulate how artificial intelligence is changing the threat landscape and how security teams can adapt their tooling and practices accordingly.
- Experience working across SaaS, firmware, IoT, cloud, and corporate security environments is highly valuable.
- Experience with C or C++ and embedded or firmware security is a plus.
- Experience in cloud-native, AI-focused environments and organizations developing AI-driven or agentic products is a plus.
- Experience with security automation platforms such as Tines and serverless technologies such as AWS Lambda is desirable.
- Experience integrating vulnerability management into modern continuous integration and continuous delivery (CI/CD) pipelines using a shift-left security approach is preferred.
- Experience working with FedRAMP-certified environments is a plus.
- Experience building, extending, or integrating AI security copilots or agents for workflows such as automated triage and remediation drafting is desirable.
- Strong analytical and problem-solving abilities, with the judgment to prioritize security risks based on business and technical impact.
- Excellent communication and collaboration skills, with the ability to influence engineering teams and senior stakeholders without relying on formal authority.
- Strong mentoring and leadership capabilities, with a track record of helping other engineers develop their technical and security expertise.
- Must be based in a U.S. Central or Eastern time zone.
- Must be authorized to work in the United States on a full-time basis.
- This position is not available to candidates residing in the San Francisco Bay Area, New York City metropolitan area, or Washington, D.C. metropolitan area.
- Relocation assistance is not provided for this position.
Benefits
- Annual base salary range of $165,200–$265,500 USD, with actual compensation varying based on location, skills, knowledge, and experience.
- Eligibility for an initial restricted stock unit (RSU) grant with no vesting cliff, plus potential ongoing refresh opportunities tied to performance and applicable plan terms.
- Competitive total compensation that may include base salary, performance-based bonus or variable pay, and equity for eligible roles.
- Flexible, employee-led working arrangements designed to support autonomy and effective collaboration.
- Comprehensive health benefits and parental leave programs.
- Professional development stipend to support ongoing learning and career growth.
- Opportunities to work on high-impact security challenges spanning cloud, software, AI, IoT, and connected hardware.
- Opportunity to influence security architecture and strategy at significant organizational scale.
- Inclusive workplace committed to equal employment opportunity and reasonable accommodations for qualified individuals with disabilities.
- A culture focused on ownership, continuous learning, collaboration, long-term impact, and professional development.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Security Engineer / Manager
Bowtie Life Insurance Company Limited Wan Chai, Hong Kong Island, Hong Kong S.A.R.
-
Manager, Cybersecurity Governance & Risk
Anglo-Eastern Ship Management Hong Kong, Hong Kong Island, Hong Kong S.A.R.
-
Information Security Engineer - Cloud Security
Ryanair Group Holdings Wrocław, Lower Silesian Voivodeship, Poland
- Nederlands Sprekende Klantadviseur Cybersecurity - Work Remote In Greece
-
Cybersecurity Expert
Inetum Lisbon, Portugal
-
Marketing Manager - Telecoms and Cybersecurity
Enea Dublin, Leinster, Ireland · €45K–€60K/yr