Application Security Engineer
Vannevar Labs · Remote
About this role
**Application Security Engineer** **About the Role** Help build security into our SaaS platform, ensuring we can quickly ship secure features to customers. Partner with software, DevOps, and platform teams to embed threat modeling, automated SAST/SCA/DAST, and rapid vulnerability response into every stage of the SDLC. **What You'll Do** • Implement and deploy enterprise standard SAST, SCA, secrets-scan, DAST, and container/IaC checks in CI/CD • Embed with development teams to run threat models, review critical PRs, and coach secure-by-default habits • Drive a shift-left vulnerability detection program to identify and remediate vulnerabilities earlier in the SDLC • Coordinate with DevOps for application security issues that cross between application and infrastructure layers • Support incident-response for product issues and feed lessons back into code, docs, and process **What You Should Have** • 5+ years in Application/Product Security • Hands-on experience securing web applications and automating AppSec workflows • Familiarity with DevSecOps practices and container security & patching • Experience with GitHub Actions, Python, TypeScript/JavaScript • Clear communicator who can translate risk for engineers **Nice to Have** • Experience securing LLM workflows • Experience with NIST Risk Management Framework • Experience with software security at a U.S. defense contractor • Active Security Clearance (or ability to obtain one) and willingness to travel onsite **Benefits** • Health, dental, and vision insurance • 100% remote - work from anywhere in the US • 401k matching • Mental health benefits • Flexible work environment • Pet and child care reimbursement during travel • Unlimited PTO **Compensation** $160,000 - $210,000 + equity + 401K match
Listing freshness
CronJobs last confirmed this listing 21h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.