Senior Application Security Engineer

Apollo.io Apollo.io · Enterprise · United States · Security

Senior Application Security Engineer responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role involves application security reviews, threat modeling, AppSec tooling, findings triage, and developer enablement, with a focus on embedding security into design, implementation, and deployment, including AI-specific security checks and controls.

What you'd actually do

  1. Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment.
  2. Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch.
  3. Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs.
  4. Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment.
  5. Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths.

Skills

Required

  • 5+ years of software engineering or application security experience
  • hands-on AppSec depth in modern SaaS environments
  • secure software development lifecycle (SSDLC)
  • threat modeling
  • application security reviews
  • vulnerability management
  • secure coding practices
  • risk assessment
  • security tooling configuration
  • automation

Nice to have

  • offensive security testing
  • exploit development
  • AI security controls
  • developer enablement

What the JD emphasized

  • AI features
  • AI security requirements
  • AI-specific security checks
  • AI-powered features

Other signals

  • AI-powered features
  • AI security requirements
  • AI-specific security checks