Senior to Staff Application Security Engineer
Job Description
This Senior to Staff Application Security Engineer role is focused on establishing an application security program from the ground up and strengthening security across APIs, web applications, and internal services. The position is onsite in Phoenix, AZ, and emphasizes proactive vulnerability discovery, secure pipeline execution, and early security involvement in new feature design.
What You Will Do
- Build and develop the application security program from the ground up.
- Identify vulnerabilities across APIs, web apps, and internal services before they can be exploited.
- Run and create SAST and DAST pipelines to support ongoing security testing.
- Manage the bug bounty program.
- Participate in new feature designs early to ensure security requirements are incorporated during development rather than added later.
Key Responsibilities
You will lead the establishment of application security practices, with an emphasis on integrating testing and secure design review into development workflows. A core part of the work involves proactively finding weaknesses in services and web-facing systems, and ensuring security is addressed during feature planning.
Required Qualifications
- 8+ years of experience in application security (AppSec), product security, or DevSecOps.
- Deep background in software development.
- Experience with SCA, DAST, SAST, and code reviews.
- Strong communication skills.
- Previous experience building application security programs from the ground up.
- Current authorization to work in the US on a full-time basis now and in the future.
Technologies and Tools
- SAST, DAST, and SCA
- Linux kernel security