Senior Application Security Engineer

Job not on LinkedIn

đŸ”„ 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Apollo.io

Apollo.io

51 - 200 employees

Founded 2015

đŸ€ B2B

☁ SaaS

đŸ€– Artificial Intelligence

B2B ‱ SaaS ‱ Artificial Intelligence

Apollo. io is an all-in-one sales platform designed to streamline and enhance sales operations from lead generation to deal management. The platform offers tools for contact and account search, scores and signals analysis, inbound optimization, sales engagement, and more, leveraging AI and a living data network for comprehensive sales intelligence. Apollo. io is ideal for sales professionals, marketers, and revenue operations teams aiming to enhance productivity and efficiency by automating workflow tasks and integrating CRM systems. With a focus on improving sales performance through analytics and conversation intelligence, Apollo. io helps businesses find the right leads at the right time, nurture those leads effectively, and close deals efficiently.

📋 Description

‱ Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment. ‱ Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch. ‱ Provide practical security architecture guidance to Engineering, Product, and IT teams. ‱ Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems. ‱ Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs. ‱ Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities. ‱ Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom. ‱ Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities. ‱ Apply clear, risk-based severity decisions using exploitability, data sensitivity, customer impact, and blast radius. ‱ Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise. ‱ Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly. ‱ Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment. ‱ Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths. ‱ Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely. ‱ Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI-safety content. ‱ Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly. ‱ Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity. ‱ Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision-making.

🎯 Requirements

‱ 5+ years of software engineering or application security experience, with meaningful hands-on AppSec depth in modern SaaS environments. ‱ Strong software development skills and the ability to read, write, and ship production code; Ruby experience is highly valuable, and Python or similar scripting ability is a plus. ‱ Strong Linux and cloud fundamentals, ideally with experience in GCP-backed environments. ‱ Deep familiarity with common AppSec issues, secure design, secure authentication and authorization patterns, vulnerability management, and developer security tooling. ‱ Demonstrated ability to perform deep code review, penetration testing, and exploit-oriented validation, and to either fix vulnerabilities directly or work closely with engineers to land durable remediations that hold up against bypass attempts and variant analysis. ‱ Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling through closure and verification. ‱ Experience using AI-assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale. ‱ Experience securing AI-powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring expectations. ‱ Strong written and verbal communication, stakeholder management, and influencing skills across technical and non-technical partners.

đŸ–ïž Benefits

‱ equity ‱ company bonus or sales commissions/bonuses ‱ 401(k) plan ‱ at least 10 paid holidays per year ‱ flex PTO ‱ parental leave ‱ employee assistance program and wellbeing benefits ‱ global travel coverage ‱ life/AD&D/STD/LTD insurance ‱ FSA/HSA and medical, dental, and vision benefits

Apply Now

Similar Jobs

🕒 June 2

Ciena

5001 - 10000

📡 Telecommunications

🔧 Hardware

Application Support Engineer at Ciena designing robust infrastructure solutions for high-speed connectivity. Managing system reliability through proactive monitoring and incident management.

🇹🇩 Canada – Remote

đŸ’” $78.5k - $125.5k / year

💰 Series C on 1995-12

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ’» Application Engineer

🕒 May 28

Switzerland Global Enterprise

51 - 200

đŸ€ B2B

đŸ›ïž eCommerce

Lead Application Engineer defining technical requirements for IEC 61850 solutions at GE Vernova. Collaborating with cross-functional teams in a remote work environment.

🇹🇩 Canada – Remote

đŸ’” $105.3k - $142.3k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ’» Application Engineer

🕒 May 28

GE Vernova

10,000+ employees

⚡ Energy

🚀 Aerospace

đŸ€– Artificial Intelligence

Lead Application Engineer defining technical requirements for IEC 61850 architectures in Green Energy transition. Collaborating with teams to resolve issues and develop controller solutions.

🇹🇩 Canada – Remote

đŸ’” $105.3k - $142.3k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ’» Application Engineer

🕒 May 28

Acuity

10,000+ employees

⚡ Energy

Advanced Applications Engineer providing system support and training for Q-SYS solutions across Canada. Collaborating with partners and users to enhance audio, video, and control systems.

🇹🇩 Canada – Remote

đŸ’” $66.7k - $120k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ’» Application Engineer

Lua

🕒 May 26

Miratech

501 - 1000

Java Developer developing and improving cloud-based IVR applications for Miratech. Collaborating with project teams to ensure high-quality implementation and support in voice contact center systems.

🇹🇩 Canada – Remote

💰 Private Equity Round on 2022-04

⏰ Full Time

🟡 Mid-level

🟠 Senior

đŸ’» Application Engineer