Staff Application Security Engineer
Location: Remote
Compensation: Salary
Reviewed: Fri, Oct 02, 2026
This job expires in: 30 days
Job Summary
Owning the security posture of products from design through release, the full-time remote Staff Application Security Engineer will manage the secure development lifecycle, product vulnerability management, and product security for both on-premise and SaaS offerings.
Key responsibilities
- Lead the maturation of the secure software development lifecycle (SSDLC), including security requirements and threat modeling
- Oversee the penetration testing program and manage the application and product vulnerability lifecycle
- Drive the Product Security Roadmap by collaborating with Product Management and Engineering to prioritize and implement security features
Required qualifications
- 6+ years of experience in application security, product security, or secure software engineering
- Strong proficiency in an object-oriented programming language, preferably Java, with the ability to read and write production-quality code
- Deep knowledge of application attack surfaces, including authentication, authorization, and API security
- Hands-on experience with integrating and tuning security tools in CI/CD pipelines
- Experience with coordinated disclosure and managing communications with external security researchers
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 41,560 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee