EngineerJobs.io
← Back to all jobs

Job Description

Own application security end to end across the delivery lifecycle, from source code and CI/CD to cloud runtime.

Responsibilities

  • Own the scanning and posture platform end to end across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, maintaining a false-positive rate engineers trust.
  • Build automation to route, deduplicate, and prioritize findings, with owner resolution, SLA tracking, and closure verification.
  • Build and run policy-based blocking controls in pull requests and CI/CD pipelines using policy-as-code centrally, scoped to repository tiering so coverage inherits to future repositories.
  • Turn a gate on only when the baseline is triaged and false positives are under the bar, and ensure teams have a path forward when controls apply.
  • Author application security standards, secure design patterns, and remediation SLAs the organization builds against.
  • Own the exception and risk-acceptance workflow and report on risk reduced rather than finding counts.
  • Make threat modeling repeatable through templates and AI-assisted triage, producing testable requirements.
  • Participate in architecture and design reviews with principal engineers and make security decisions in-room, including token versus service identity needs, authorization patterns for list endpoints, and preventing services from taking authorization attributes from callers.
  • Review third-party integrations before production.
  • Set the technical bar by coaching and reviewing the security work of a champions network and third-party testing partners, and mentoring engineers added to the team.
  • Be the point of contact engineering calls for explaining what a finding means and does not mean, supporting same-day responses for blocked developers.
  • Own security testing of the running application (not only source), coordinate remediation with developers, and verify outcomes on retest.
  • Lead response when a critical vulnerability or exploit is identified.
  • Lead security integration of acquired engineering environments by bringing repositories, pipelines, and cloud accounts under coverage without stalling delivery.

Requirements

  • 8+ years in application security, product security, DevSecOps, or security engineering, with most experience hands-on versus advisory.
  • Hands-on experience owning an enterprise-scale security program across multiple teams and stakeholders with limited oversight, including setting standards others follow and reviewing other engineers’ work.
  • Depth in a cloud-native application protection or application security posture platform, such as Wiz, Snyk, Prisma Cloud, or Orca, including writing policy and building on its API.
  • Shipped pipeline enforcement: policy-based blocking in pull requests and CI/CD, security policy-as-code, and practical experience moving from advisory to blocking without engineering revolt.
  • Threat modeling experience applied to real systems, using STRIDE or an equivalent, extended with MITRE ATLAS and LLM risk taxonomies for AI-enabled systems.
  • Architecture-level security judgment for distributed authorization design: trust boundaries, token validation, service-to-service identity, and object-level access control.
  • Approachable and constructive under pressure, able to identify launch risks without becoming a workaround driver.
  • Automation-first, AI-forward approach, including a defensible view on securing AI itself: validating AI-generated code and agentic risk such as prompt injection, tool permissions, and the MCP supply chain.
  • Dynamic testing of running applications and APIs using DAST, API security testing, or hands-on offensive work, plus cloud security depth in a major public cloud ( Google Cloud preferred).
  • Coding ability in Python, Go, or TypeScript, with writing that is tight and evidence-backed.

Technologies

  • Wiz
  • Snyk
  • Prisma Cloud
  • Orca
  • STRIDE
  • MITRE ATLAS
  • Python
  • Go
  • TypeScript
  • Google Cloud
  • DAST
  • MCP

Benefits

  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • PTO, company holidays, and parental leave
  • Paid Time Off/Paid Sick Leave (15 days of paid time off during first year; increased accruals after five years)
  • Paid training and certifications
  • Legal assistance and identity protection
  • Pet insurance
  • Employee assistance program (EAP)

Education & Certifications

  • Bachelor’s in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred.
  • Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect.
  • CSSLP, GWAPT, OSWE, or OSCP a plus.

Compensation

  • Base pay range: $101,300 - $172,000 per yearly
  • Annual performance bonus

Location: Vancouver, WA (onsite)

Similar Jobs