Senior Software Engineer, Application Security – AV and Software Infrastructure
Job Description:
- Review application designs and code, develop threat models, and help teams address security risks before deployment
- Design and implement authentication and authorization controls for APIs, services, and applications, including service identities, tenant isolation, and resource-level access
- Build reusable libraries, tooling, and reference implementations that make secure patterns straightforward to adopt
- Improve how applications handle credentials, secrets, sensitive data, and security-relevant logging
- Integrate practical security checks into development and CI/CD workflows, with actionable findings and clear remediation paths
- Investigate application vulnerabilities, develop fixes with service owners, and add regression coverage
- Partner with infrastructure and corporate security teams to prioritize improvements and measure their effectiveness
Requirements:
- 12+ years of relevant experience
- BS or MS in Computer Science, Computer Engineering, or a related field, or equivalent experience
- Experience building and operating production software, with substantial work in application or product security
- Strong programming skills in Go, Python, Java, C++, or a comparable language
- Ability to review and modify unfamiliar code
- Practical understanding of web and API security, authentication, authorization, and common vulnerability classes
- Experience with threat modeling and security reviews for distributed systems
- Ability to turn security findings into concrete engineering changes and prioritize work based on risk and impact
- Clear communication and experience working collaboratively with engineering teams
- Experience with OAuth 2.0, OpenID Connect, service identity, and authorization policy systems
- Experience securing multi-tenant services, data platforms, or developer infrastructure
- Familiarity with Kubernetes, cloud IAM, infrastructure as code, and CI/CD systems
- Experience improving vulnerability detection or dependency security while reducing noisy findings
- A record of building security capabilities that engineering teams adopt and use
Benefits:
- Equity
- Benefits