Senior Security Engineer, Application & Platform Security

Sentry Sentry · Enterprise · San Francisco, CA · Security

This role is for a Senior Security Engineer at Sentry, a company that provides performance and error monitoring tools. The engineer will be responsible for application and platform security, including security reviews, threat modeling, vulnerability management, and embedding secure coding practices. A key aspect of the role involves addressing the security challenges introduced by Sentry's expanding agentic product capabilities and AI-assisted engineering practices. The role requires influencing security practices, championing secure-by-design principles, and evaluating emerging threats. While the company is developing AI-related features, this role is focused on securing those systems rather than building them.

What you'd actually do

  1. Own and mature Sentry's security review program. From secure code review, to architecture review, and threat modeling. You will build processes, tooling, and culture which makes security a natural part of how we ship and operate.
  2. Influence mature vulnerability management practices. Intake, triage, prioritization, remediation tracking, and management of our bug bounty and responsible disclosure program.
  3. Champion secure-by-design principles. Partner with engineering and product teams to embed security early in the development lifecycle and integrate security tooling into developer and CI/CD workflows.
  4. Validate and reproduce application and infrastructure security findings. Scanning, manual testing, coordinate penetration testing and vulnerability validation across Sentry's application, SDKs and cloud-based platform.
  5. Evaluate and respond to emerging threats relevant to application security Sentry. We build and operate a complex application and cloud environment, including the novel attack surface introduced by Sentry's agentic product features and AI-assisted engineering practices.

Skills

Required

  • 5+ years of industry experience designing, building, securing complex applications and large-scale distributed cloud systems
  • Degree in Computer Science or a related field, equivalent training, or professional experience
  • Direct experience with security reviews, SDLC practices, secure CI/CD, architecture reviews, threat modeling, vulnerability management, bug bounty and responsible disclosure programs
  • Experienced and comfortable programming in at least one language, must be comfortable reviewing Python, Typescript, Go, Rust applications
  • Familiarity with using distributed cloud technology (AWS, GCP, Azure, Kubernetes, Docker, Terraform, etc.) and securing those technologies (cloud networking, IAM, etc.)
  • A collaborative approach to problem solving paired with strong written and verbal communication

Nice to have

  • security reviews
  • threat modeling
  • vulnerability management
  • secure coding practices
  • agentic product capabilities
  • AI-assisted engineering practices

What the JD emphasized

  • novel attack surface introduced by Sentry's agentic product features and AI-assisted engineering practices
  • novel agentic architecture