Application Security Engineer
Cerebras · Sunnyvale, CA
About this role
## Application Security Engineer ### About the role Cerebras Systems builds the world’s largest AI chip—an architecture designed to deliver industry-leading training and inference speeds. We’re looking for an **Application Security Engineer** with a strong focus on **Vulnerability Management** to help secure Cerebras software, infrastructure, and AI platforms. You will **own and evolve** key parts of our vulnerability management program—from **vulnerability discovery and risk prioritization** through **remediation and verification**. This is **not** a ticket-management role. We’re seeking an engineer who can understand vulnerabilities in context, partner directly with engineering teams, automate repetitive security work, and help eliminate **classes of vulnerabilities** rather than only tracking individual findings. ### Responsibilities - Own and continuously improve vulnerability management across **applications, software dependencies, containers, operating systems, cloud infrastructure, and externally exposed services**. - Use **AI agents and advanced security models** to augment vulnerability discovery, code analysis, adversarial testing, prioritization, and remediation. - Analyze vulnerabilities beyond scanner severity using **exploitability, exposure, affected assets, available mitigations, and business impact**. - Partner with engineering teams to **triage findings**, determine remediation, and drive vulnerabilities to closure within **risk-based SLAs**. - Build automation for **vulnerability ingestion, deduplication, enrichment, prioritization, assignment, remediation tracking, and reporting**. - Identify systemic vulnerability patterns and work on **root causes** with engineering teams. - Operate and improve application security capabilities including **SAST, SCA, secrets detection, container scanning, infrastructure scanning, and external attack-surface monitoring**. - Validate findings through technical investigation and hands-on testing to distinguish **exploitable issues** from false positives and low-risk findings. - Perform targeted application security reviews and testing for **high-risk services and features**. - Integrate security controls into **CI/CD and developer workflows** with minimal friction. - Develop metrics and reporting for visibility into **vulnerability exposure, remediation performance, recurring vulnerability classes, and security risk**. - Evaluate and integrate new security technologies as environments evolve. - Partner on incident response when vulnerabilities are actively exploited or require urgent remediation. ### Skills & Qualifications - Strong application/product security fundamentals and **hands-on vulnerability management** experience. - Understanding of common vulnerability classes and exploitation techniques across **web apps, APIs, authentication, cloud services, containers, and software supply chains**. - Ability to read and reason about code and work effectively with software engineers on practical remediation. - Experience with vulnerability scanning and application security technologies such as **SAST, SCA, DAST, secrets scanning, container scanning, or CSPM**. - Knowledge of vulnerability prioritization concepts including **CVSS, exploitability, asset criticality, internet exposure, compensating controls, and threat intelligence**. - Comfortable investigating findings manually (not relying exclusively on scanner output). - Ability to automate security workflows using **Python, Go,
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.