Search Remote Jobs

Staff Application Security Engineer

🔥 21 hours ago

🇺🇸 United States – Remote

đź’µ $143k - $214k / year

⏰ Full Time

đź”´ Lead

đź’» Application Engineer

đź‘» Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Shield AI

Shield AI

501 - 1000 employees

Founded 2015

🤖 Artificial Intelligence

🚀 Aerospace

🎖️ Defense

Artificial Intelligence • Aerospace • Defense

Shield AI is a leading developer of AI-driven military solutions, focusing on enhancing mission autonomy and battlefield awareness. Their platform, Hivemind, enables rapid deployment of intelligent systems for various defense applications, including drone operation and surveillance. With a commitment to utilizing advanced technology, Shield AI aims to protect service members and civilians by revolutionizing defense technologies through autonomous systems.

đź“‹ Description

• Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements • Translate security policy into clear, achievable requirements for development, product, and platform teams • Assess maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead improvement roadmaps • Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials • Partner with development teams to identify, triage, prioritize, remediate, and verify application-security findings • Evaluate, implement, tune, and operationalize SAST, DAST, SCA, secrets detection, infrastructure-as-code security scanning, container/image scanning, API, and cloud-native security controls • Ensure security tooling produces actionable findings and minimizes false positives • Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews • Establish risk-based vulnerability management, remediation SLOs, compensating controls, risk acceptance, escalation, and exception management • Develop processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies • Establish open-source software governance, component inventory, license identification and review, approval workflows, and policy enforcement • Mature software supply-chain security practices, including SBOMs, VEX, build and release provenance, artifact/package/container/binary signing, artifact verification, trusted promotion, secure repositories, approved dependency sources, and SLSA-aligned controls • Partner with DevOps and platform engineering to secure CI/CD pipelines, source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines • Support vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage, and product-security incident response • Create and lead a security champions program with secure-coding guidance, training, office hours, practical tools, and timely security engagement • Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity • Support customer, regulatory, audit, and assurance activities related to secure development and software supply-chain practices

🎯 Requirements

• 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related field • Experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams • Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles • Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices • Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling • Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows • Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition • Knowledge of authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities • Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management • Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes • Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable frameworks • Ability to read and assess production code and scripts in one or more modern programming languages • Strong written and verbal communication skills • Preferred: experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls • Preferred: experience with VEX, CSAF, SPDX, CycloneDX, and component or vulnerability intelligence workflows • Preferred: experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code • Preferred: experience with source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms • Preferred: experience with Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies • Preferred: experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements • Preferred: relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials • Offers contingent on a cleared background and possible reference check

🏖️ Benefits

• Bonus • Benefits package • Equity • Temporary benefits package applicable after 60 days of employment (temporary employees) • Remote work arrangement • Equal employment opportunity and workplace accommodation support

Apply Now

Similar Jobs

đź•’ September 15

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Staff Application Security Engineer leading vulnerability management and application security for Samsara’s Connected Operations Cloud. Automating protection across cloud, IoT firmware, and corporate systems.

đź•’ September 15

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Staff Application Security Engineer guiding vulnerability management and application security for Samsara’s IoT-connected operations platform. Driving automation, remediation, and cloud, firmware, and corporate security programs.

đź•’ September 15

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Staff Application Security Engineer defining vulnerability management and application security for Samsara’s IoT-connected operations platform. Driving automation, remediation, and security direction across cloud, firmware, and corporate systems.

đź•’ September 15

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Staff Application Security Engineer directing vulnerability management and application security for Samsara’s IoT-powered Connected Operations Cloud. Automating detection, remediation, and critical vulnerability response across cloud, firmware, and corporate systems.

đź•’ September 5

Thermal Scientific Works

11 - 50

🏭 Manufacturing

🔬 Science

đź”§ Hardware

Application Engineer supporting ThermalWorks’ zero-water data-center cooling systems through design review, equipment application, estimating, and customer engineering support.