Senior Application Security Engineer

Temporal · Enterprise · United States · Security

Senior Application Security Engineer responsible for securing the Temporal development pipeline, product, and customer execution environment. Will collaborate with engineering teams and customers to build security into the platform and shape responsible AI usage in product and engineering processes.

What you'd actually do

  1. Collaborate with product and engineering teams to integrate security principles into the design and architecture of products.
  2. Conduct threat modeling and risk assessments to identify vulnerabilities and potential attack vectors across the full product surface.
  3. Manage the Secure Development pipeline including code security and 3rd party library supply chain security.
  4. Stay current on emerging standards and guidance (e.g. OWASP Top 10 for LLMs, MCP security specifications) and translate these into actionable internal policy.
  5. Triage Bug Bounty findings and responsibility disclosed vulnerabilities.

Skills

Required

  • Application security
  • Product security
  • Secure Development pipeline
  • Code security
  • 3rd party library supply chain security
  • Threat modeling
  • Risk assessments
  • SAST
  • DAST
  • Penetration testing frameworks
  • Application architecture
  • Design principles
  • Multi-programming language vulnerability identification
  • Encryption
  • Authentication
  • Secure communication protocols
  • Kubernetes security posture management
  • Auditing
  • Workload hardening
  • RBAC design
  • Admission control
  • Multi-tenant security architecture
  • Data plane isolation
  • Control plane hardening
  • Cross-tenant data leakage prevention
  • Python
  • Go

Nice to have

  • Distributed computing
  • Security Champions program
  • Open Source automation
  • Security conference talks
  • Published research

What the JD emphasized

  • OWASP Top 10 for LLMs
  • multi-tenant security architecture