EngineerJobs.io
← Back to all jobs

Job Description

Gemini’s AppSec team is hiring a Staff Application Security Engineer to set technical direction for securing high-impact attack surfaces and to build AI-assisted security capabilities across the agentic SDLC.

Responsibilities

  • Own and continuously improve Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert
  • Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services
  • Design and build AI agents across the SDLC, including:
    • Automated threat modeling during design
    • AI-driven secure code generation and review
    • Reducing AppSec toil
  • Develop and deliver hands-on application security training to enable engineers at scale
  • Participate in the Application Security on-call rotation and lead post-incident hardening

Requirements

  • Proven ability to conduct design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset
  • Strong application security foundation and familiarity with common vulnerabilities such as SSRF, race conditions, and privilege escalations
  • Deep code review experience in Scala, Java, Go or other common languages, plus hands-on experience in at least Python, Go, or similar for building; comfortable reviewing production services in other languages
  • Experience implementing custom detection and prevention application security controls to address issues beyond OWASP Top 10
  • Familiarity with highly regulated environments (financial services, fintech, crypto, or equivalent) and ability to connect business objectives with security risk
  • Strong cross-functional communication and collaboration with Security, Engineering, and Product
  • Typically 7-10+ years of experience (or equivalent impact) in application security, product security, or related roles

Preferred Qualifications

  • Experience building AI application security tooling using agents or related skills
  • Experience with supply chain security, common frameworks like SLSA and OWASP SPVS, and other CI/CD security controls
  • Experience preventing application security vulnerabilities at scale through secure design patterns, automated tooling, or frameworks
  • Experience with microservice architectures and cloud-native environments

Technologies

  • Scala
  • Java
  • Go
  • Python
  • OWASP Top 10
  • SSRF
  • SLSA
  • OWASP SPVS

Compensation

  • Base salary range: $168,000 - $240,000 per year (New York, NY)
  • Base range does not include discretionary bonus or equity package
  • Compensation factors include skillset, experience, job scope, and current market data

Benefits

  • Competitive starting pay
  • Discretionary annual bonus
  • Long-term incentive: new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Paid Parental Leave
  • Flexible time off

Work Approach and Location

  • Hybrid work in the United States at company hub offices
  • All employees are required to onboard in-person at an office location
  • Role location: New York, NY (hybrid)

Equal Employment Opportunity

  • Gemini is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status
  • Accommodations are available; contact the People Team for specific needs

Similar Jobs