Senior Security Engineer, Application Security

Handshake · Enterprise · San Francisco, CA · Engineering

Senior Application Security Engineer responsible for building systems, tools, and automation to embed security into the software development lifecycle in an AI-enabled environment. Focuses on developer-facing tooling, threat modeling, vulnerability management, and leveraging AI/agentic tools to scale security impact.

What you'd actually do

  1. Own and grow key areas of our Secure Software Development Lifecycle (SDLC) like threat modeling, security reviews, and vulnerability management.
  2. Work collaboratively with and be a trusted partner for engineering teams.
  3. Eliminate whole classes of vulnerabilities by building secure by default libraries and tools into our platform.
  4. Raise the bar for security awareness by teaching others and sharing your knowledge
  5. Design and build developer facing tooling to help engineers identify and fix security issues before they make it to production.

Skills

Required

  • Secure Software Development Lifecycle (SDLC)
  • threat modeling
  • security reviews
  • vulnerability management
  • common application security risks (OWASP Top 10)
  • mitigation strategies
  • cloud-native security
  • developer facing tooling
  • cloud provider security
  • communication skills
  • risk assessment

Nice to have

  • Google Cloud (GCP)
  • Ruby
  • Typescript
  • Go
  • agentic systems for security

What the JD emphasized

  • AI-enabled environment
  • AI and agentic tooling
  • AI and agenting tooling