Loading...

Staff Application Security Engineer

  • Company: Get A Job.ai
  • Location: USA
  • Salary: Pay not listed
  • Work type: Remote

Website Get A Job.ai

Represented by Get A Job.ai

About This Role

We are representing a confidential fintech organization seeking a Staff Application Security Engineer to own and scale their application security program. Reporting to the Product Security Manager, you'll reduce real risk across mobile, web, and cloud systems by driving remediation, building engineering guardrails, and creating security guidance that developers actually use.

This role works both sides of the AI security challenge: using AI to perform security work more effectively, and securing the AI systems being built into production. If you transitioned into security from a product engineering background, our client is especially interested in speaking with you.

Responsibilities

  • Own the application security program including standards, vulnerability management pipeline, and guardrails that prevent entire classes of defects from recurring
  • Drive vulnerability management outcomes by triaging and tuning findings from scanning, code review, and annual penetration tests, then partnering with engineering teams to ship and verify fixes
  • Lead application security reviews and threat models for high-impact work across mobile, web, and backend systems, documenting risk decisions with clear mitigation plans
  • Review and threat model agentic AI workflows, defining security controls for tool use, data access, and action execution
  • Build and improve automation that triages findings, prioritizes them with service context, and produces actionable remediation guidance for engineers
  • Build scalable guardrails including repository baselines, required checks in GitHub, secure-by-default patterns for cloud workloads, reusable templates, and a security champions program

What We're Looking For

  • 6+ years in application or product security, or equivalent depth in secure software engineering with meaningful application security ownership
  • Strong Python code review skills—you can open a Lambda function, understand its purpose, and explain to the author exactly what's wrong and why
  • A track record of shipping security improvements that reduced real risk, not just running scanners or writing policy—you can point to fixes that landed, were verified, and to remediation you drove across teams you didn't own
  • Experience with threat modeling and secure design review, engaging with designs before they ship, not only with code after the fact
  • Practical, everyday use of AI in your security work—this is about how you already work, not a tool you've tried once
  • Working knowledge of AWS security (Lambda, API Gateway, IAM least privilege, secrets handling) and CI/CD security in GitHub Actions—depth in the underlying mechanics matters more than years in any one platform

Technology stack includes: GitHub (Actions, Advanced Security), Python, Terraform, AWS services (Lambda, API Gateway, IAM, DynamoDB, S3, SNS, SQS, VPCs), Snowflake, SQL, and AI tooling.

How We Work With You

Get A Job.ai is exclusively representing this confidential client. When you apply through our platform, one of our recruiters will conduct an initial screening to understand your background and assess fit. If we move forward together, we will submit your profile to the client for consideration. Please do not attempt to contact the client directly, as all communication should flow through Get A Job.ai to ensure a coordinated process.

Pay

Compensation details will be discussed during the screening process with our recruiting team.

Location: USA

Equal Employment Opportunity

Get A Job.ai is committed to inclusive hiring practices and providing equal employment opportunities to all qualified candidates regardless of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We welcome all applicants and will provide reasonable accommodations during the application process upon request.

Apply with Get A Job.ai

A recruiter will review your profile and submit you to the client. Do not contact the client directly.

More options

Apply with Get A Job.ai

Apply through Get A Job.ai. A recruiter will review your profile and submit you. Do not contact the client directly.

Apply through Get A Job.ai. A recruiter will review your profile and submit you.

Local insights for this role are preparing — this section updates automatically in a few seconds (or refresh).

Listing facts

  • Role Staff Application Security Engineer
  • Employer Get A Job.ai
  • Location USA · Remote-friendly
  • Type Full Time
  • Pay (from listing) Pay not listed
  • Posted September 6, 2026
  • Apply by October 6, 2026
  • Country United States
  • Overview Full job description on this page (561 words)

Facts above come from this job record on Get A Job.AI — not copied from third-party review sites.

Limited public data for this employer

We only show facts we can ground in public sources (Wikidata, O*NET, news/discussion links, or this listing). We do not invent Glassdoor-style ratings, salaries, or testimonials when data is thin. Use the listing facts, occupation context, and related openings below while we continue researching.

Explore related openings

Occupation family: Application Security Engineer

Keep exploring on Get A Job.ai

Not quite the right fit? Your next opportunity is a click away.

Hiring instead? Post a job and reach candidates searching right now.

Staff Application Security Engineer Get A Job.ai · USA