Senior Application Security Engineer

Webflow Webflow · Enterprise · CA · Remote · Engineering

Senior Application Security Engineer at Webflow, a company leveraging AI in its platform. The role focuses on enhancing secure development practices, identifying vulnerabilities, and contributing to security controls. It involves working with AI tools for security reviews and automation, and supporting compliance frameworks.

What you'd actually do

  1. Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem.
  2. Bring security best practices to the software development lifecycle.
  3. Work as part of a team to champion security standards while balancing business strategies and requirements.
  4. Support Webflow’s security current and future compliance frameworks
  5. Work to find security vulnerabilities through grey-box techniques, and propose solutions at the architecture and code level to mitigate findings.

Skills

Required

  • Application security experience
  • Hands-on software development
  • Secure software design
  • Secure coding
  • Modern web application security
  • Threat modeling
  • Penetration testing
  • SCA Supply Chain
  • SAST
  • DAST
  • Bug bounty programs
  • Security controls
  • Authorization models
  • Security features
  • Incident response
  • AI coding agents

Nice to have

  • Building automation that leverage agentic AI

What the JD emphasized

  • 5+ years of application security experience
  • hands-on software development
  • high-complexity, large-scale applications
  • secure software design
  • secure coding
  • modern web application security
  • identify security design flaws and business-logic vulnerabilities
  • drive risk-based remediation
  • led threat modeling efforts
  • conducted penetration testing
  • manage third-party pentests
  • managed one or more of application security programs or tooling initiatives such as SCA Supply Chain, SAST, DAST
  • led bug bounty programs
  • contributed to security controls within large-scale solutions
  • designing and/or delivering security features directly into applications
  • using and building automation that leverage agentic AI
  • applying AI coding agents to scale security reviews, detection, and automation responsibly
  • participated in response efforts for application security incidents