Lead Application Security Engineer, Code to Cloud
Job Description
Own application security end to end across the delivery lifecycle, from source code and CI/CD to cloud runtime.
Responsibilities
- Own the scanning and posture platform end to end across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, maintaining a false-positive rate engineers trust.
- Build automation to route, deduplicate, and prioritize findings, with owner resolution, SLA tracking, and closure verification.
- Build and run policy-based blocking controls in pull requests and CI/CD pipelines using policy-as-code centrally, scoped to repository tiering so coverage inherits to future repositories.
- Turn a gate on only when the baseline is triaged and false positives are under the bar, and ensure teams have a path forward when controls apply.
- Author application security standards, secure design patterns, and remediation SLAs the organization builds against.
- Own the exception and risk-acceptance workflow and report on risk reduced rather than finding counts.
- Make threat modeling repeatable through templates and AI-assisted triage, producing testable requirements.
- Participate in architecture and design reviews with principal engineers and make security decisions in-room, including token versus service identity needs, authorization patterns for list endpoints, and preventing services from taking authorization attributes from callers.
- Review third-party integrations before production.
- Set the technical bar by coaching and reviewing the security work of a champions network and third-party testing partners, and mentoring engineers added to the team.
- Be the point of contact engineering calls for explaining what a finding means and does not mean, supporting same-day responses for blocked developers.
- Own security testing of the running application (not only source), coordinate remediation with developers, and verify outcomes on retest.
- Lead response when a critical vulnerability or exploit is identified.
- Lead security integration of acquired engineering environments by bringing repositories, pipelines, and cloud accounts under coverage without stalling delivery.
Requirements
- 8+ years in application security, product security, DevSecOps, or security engineering, with most experience hands-on versus advisory.
- Hands-on experience owning an enterprise-scale security program across multiple teams and stakeholders with limited oversight, including setting standards others follow and reviewing other engineers’ work.
- Depth in a cloud-native application protection or application security posture platform, such as Wiz, Snyk, Prisma Cloud, or Orca, including writing policy and building on its API.
- Shipped pipeline enforcement: policy-based blocking in pull requests and CI/CD, security policy-as-code, and practical experience moving from advisory to blocking without engineering revolt.
- Threat modeling experience applied to real systems, using STRIDE or an equivalent, extended with MITRE ATLAS and LLM risk taxonomies for AI-enabled systems.
- Architecture-level security judgment for distributed authorization design: trust boundaries, token validation, service-to-service identity, and object-level access control.
- Approachable and constructive under pressure, able to identify launch risks without becoming a workaround driver.
- Automation-first, AI-forward approach, including a defensible view on securing AI itself: validating AI-generated code and agentic risk such as prompt injection, tool permissions, and the MCP supply chain.
- Dynamic testing of running applications and APIs using DAST, API security testing, or hands-on offensive work, plus cloud security depth in a major public cloud ( Google Cloud preferred).
- Coding ability in Python, Go, or TypeScript, with writing that is tight and evidence-backed.
Technologies
- Wiz
- Snyk
- Prisma Cloud
- Orca
- STRIDE
- MITRE ATLAS
- Python
- Go
- TypeScript
- Google Cloud
- DAST
- MCP
Benefits
- Annual performance bonus
- 401(k) with employer match
- Medical, dental, and vision insurance
- PTO, company holidays, and parental leave
- Paid Time Off/Paid Sick Leave (15 days of paid time off during first year; increased accruals after five years)
- Paid training and certifications
- Legal assistance and identity protection
- Pet insurance
- Employee assistance program (EAP)
Education & Certifications
- Bachelor’s in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred.
- Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect.
- CSSLP, GWAPT, OSWE, or OSCP a plus.
Compensation
- Base pay range: $101,300 - $172,000 per yearly
- Annual performance bonus
Location: Vancouver, WA (onsite)