Application Security Engineer

Rubrik Rubrik · Enterprise · United States · Remote · Information Security

Application Security Engineer responsible for integrating security controls into the SDLC, architecting agentic scaffolding for AI agents performing vulnerability triage and remediation, and performing security assessments. The role emphasizes building scalable security operations through AI agents and automating vulnerability discovery and remediation.

What you'd actually do

  1. Architect the agentic scaffolding, including containment boundaries and intervention points, required to govern and scale AI agents performing machine-speed vulnerability triage, research, and remediation.
  2. Perform security assessments of applications, identifying vulnerabilities and weaknesses through both automated and manual testing techniques.
  3. Assist in identifying and implementing frictionless "shift-left" strategies to seamlessly and proactively prevent vulnerabilities earlier in the SDLC.
  4. Work with development teams, operations, governance, and other stakeholders to document security guidance, processes and standards for Rubrik products and services

Skills

Required

  • Application Security
  • SDLC activities
  • threat modeling
  • secure code review
  • vulnerability management
  • penetration testing
  • frontier models
  • agentic workflows
  • security operations
  • vulnerability discovery
  • remediation
  • regulatory guidelines
  • web attack vectors
  • application attack vectors
  • cloud attack vectors
  • programming languages (Python, Go, Scala, C/C++, Javascript/Typescript)
  • CI/CD pipeline
  • containerization (Kubernetes, Docker, etc)
  • MicroServices
  • public cloud provider (AWS, GCP, Azure)
  • application security maturity model frameworks
  • deploying and securing SaaS applications
  • securing cloud environments
  • critical thinking
  • problem solving skills
  • written communication skills
  • verbal communication skills

Nice to have

  • BS or MS in Computer Science, Information Technology, or a related field

What the JD emphasized

  • agentic scaffolding
  • AI agents
  • vulnerability triage
  • remediation
  • scale security operations
  • automating the end-to-end lifecycle of vulnerability discovery and remediation
  • FedRAMP
  • SOC2
  • ISO 27001

Other signals

  • AI agents
  • vulnerability triage
  • automation