Staff Application Security Engineer
Agent
Ai Security
Application Security
Data Security
Incident Response
Information Security
InfoSec
Management
Programming
Risk Management
Secure Software Development Lifecycle
Security
Security Architecture
Security Automation
Security Compliance
Security Operations
Security Standards
Security Testing
Solution Architecture
Specialist
Job Description
Gemini’s AppSec team is hiring a Staff Application Security Engineer to set technical direction for securing high-impact attack surfaces and to build AI-assisted security capabilities across the agentic SDLC.
Responsibilities
- Own and continuously improve Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert
- Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services
- Design and build AI agents across the SDLC, including:
- Automated threat modeling during design
- AI-driven secure code generation and review
- Reducing AppSec toil
- Develop and deliver hands-on application security training to enable engineers at scale
- Participate in the Application Security on-call rotation and lead post-incident hardening
Requirements
- Proven ability to conduct design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset
- Strong application security foundation and familiarity with common vulnerabilities such as SSRF, race conditions, and privilege escalations
- Deep code review experience in Scala, Java, Go or other common languages, plus hands-on experience in at least Python, Go, or similar for building; comfortable reviewing production services in other languages
- Experience implementing custom detection and prevention application security controls to address issues beyond OWASP Top 10
- Familiarity with highly regulated environments (financial services, fintech, crypto, or equivalent) and ability to connect business objectives with security risk
- Strong cross-functional communication and collaboration with Security, Engineering, and Product
- Typically 7-10+ years of experience (or equivalent impact) in application security, product security, or related roles
Preferred Qualifications
- Experience building AI application security tooling using agents or related skills
- Experience with supply chain security, common frameworks like SLSA and OWASP SPVS, and other CI/CD security controls
- Experience preventing application security vulnerabilities at scale through secure design patterns, automated tooling, or frameworks
- Experience with microservice architectures and cloud-native environments
Technologies
- Scala
- Java
- Go
- Python
- OWASP Top 10
- SSRF
- SLSA
- OWASP SPVS
Compensation
- Base salary range: $168,000 - $240,000 per year (New York, NY)
- Base range does not include discretionary bonus or equity package
- Compensation factors include skillset, experience, job scope, and current market data
Benefits
- Competitive starting pay
- Discretionary annual bonus
- Long-term incentive: new hire equity grant
- Comprehensive health plans
- 401K with company matching
- Paid Parental Leave
- Flexible time off
Work Approach and Location
- Hybrid work in the United States at company hub offices
- All employees are required to onboard in-person at an office location
- Role location: New York, NY (hybrid)
Equal Employment Opportunity
- Gemini is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status
- Accommodations are available; contact the People Team for specific needs