Unlock Full Resume Report

New offer - be the first one to apply!

September 17, 2026

Senior Application Security Engineer

Senior • Hybrid

165,000 - 200,000 USD/yr

San Francisco, CA

Quick Facts

Hybrid role (3 days/week in the San Francisco office). Focus: application security and embedding security into the SDLC for AI-driven healthcare software.

Description

As a Senior Application Security Engineer, you will partner with engineering to ensure security is integrated into the software development lifecycle. You’ll provide hands-on guidance for vulnerability remediation, perform secure code reviews, validate results, carry out threat modeling, and drive vulnerability identification using SAST, DAST, SCA, and in-house AI tooling. You’ll also translate security and privacy requirements into technical controls and build security awareness through training.

Responsibilities

  • Provide hands-on technical guidance to software developers throughout the vulnerability remediation lifecycle
  • Perform secure code reviews and validate false positive determinations
  • Coach developers on effective remediation strategies
  • Threat model products and contribute to a secure SDLC
  • Drive vulnerability identification using SAST, DAST, SCA, and in-house AI tooling
  • Manage external penetration testing
  • Support vulnerability management, risk assessment, and remediation prioritization
  • Improve vulnerability identification and translate security/privacy requirements into technical requirements
  • Deliver security awareness training on secure coding practices, security standards, and latest security threats

Requirements

  • BS in Computer Science (or related) or relevant certifications with equivalent experience
  • 5+ years of total experience with at least 1 year working in application security or performing security tasks in a development role
  • Contributed to secure SDLC activities: threat modeling, code review, security testing, and vulnerability management
  • Experience writing and maintaining code in at least one modern programming language and at least one scripting language (C++/Python)
  • Comfortable with testing frameworks and CI/CD pipelines
  • Experience using AI code tools (e.g., Claude Code, GitHub Copilot) for development and security testing
  • Ability to reason about risk and communicate it to technical and non-technical audiences
  • Experience with or ability to discuss current AI security threats for machine learning and generative AI

Benefits

  • Estimated base salary: $165,000–$200,000 per year, plus bonus and equity
  • Hybrid schedule (3 days/week in San Francisco)

Similar jobs you might like