Skip to content

Open nowPosted 7 hours ago

Application Security Engineer

Hark47 open roles

Where
San Jose
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowApplication Security EngineerHark · San Jose
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Hark's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Hark postings stay open a median of 39 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.2%30 days
This job: posted 7 hours ago

Hark median: 39 days open

The posting

About Hark

Hark is an artificial intelligence company building advanced, personalized intelligence. One that is proactive, multimodal, and capable of interacting with the world through speech, text, vision, and persistent memory.

We're pairing that intelligence with next-generation hardware to create a universal interface between humans and machines. While today's AI largely operates through chat boxes and decade-old devices, Hark is focused on what comes next: agentic systems that interact naturally with people and the real world.

To get there, we're developing multimodal models and next-generation AI hardware together, designed from the ground up as a single, unified interface for a new era of intelligent systems.

About the Role

We're hiring a Member of Technical Staff (Application Security Engineer) to own the security of the software Hark ships. You'll review design and code, find and fix vulnerabilities in our backend services, mobile apps, and third-party integrations, and build the guardrails that let engineers move fast without shipping bugs. Our agents act on behalf of users across their apps and data, so you'll also be defining how to secure LLM and agent systems, a space with very few established playbooks.

This role is hands-on; you'll be reading code, writing fixes, and building tooling, not managing or auditing.

Responsibilities

  • Threat-model new features and services, with a focus on agent/LLM attack surfaces (prompt injection, tool misuse, data exfiltration, cross-tenant access).
  • Review code and designs for Hark's backend services (primarily Go), APIs, and mobile apps; fix vulnerabilities directly when it's faster than filing a ticket.
  • Secure authentication, authorization, and session handling across our consumer product, including OAuth integrations with third-party platforms.
  • Build and tune SAST, dependency, and secrets scanning in CI so findings are high-signal and developers actually act on them.
  • Triage and remediate findings from pentests and our vulnerability disclosure program.
  • Partner with engineering to embed security into the development lifecycle through paved roads, secure defaults, and reusable libraries.

Requirements

  • 4–8 years of hands-on application or product security engineering experience.
  • Strong software engineering skills; you can read, write, and ship production code (Go strongly preferred; Python, TypeScript, Swift, or Kotlin also valuable).
  • Deep understanding of web and API vulnerability classes (OWASP Top 10, SSRF, IDOR/BOLA, authz flaws, injection) and how to fix them at the root.
  • Hands-on experience with OAuth 2.0 / OIDC, session management, and securing multi-tenant systems.
  • Experience running secure code review and threat modeling in a fast-moving engineering org.
  • Experience turning scanner and runtime findings into fixes using tools like Wiz Code, Wiz Cloud, and Datadog SIEM (or equivalent SAST/SCA, CNAPP, and SIEM tools).
  • Real curiosity about LLM and agent security; this is new territory and we want someone excited to figure it out.

Bonus Qualifications

  • Experience at a security-forward product company (Stripe, Coinbase, Discord, Roblox, Netflix) or an offensive security consultancy (Trail of Bits, Bishop Fox, NCC Group).
  • Mobile application security experience (iOS/Android).
  • Prior work on LLM/agent threat modeling, prompt injection defenses, or AI red teaming.
  • Bug bounty, CVE, or open source security contributions.

Compensation

The US base salary range for this full-time position is between $150,000 - $300,000 annually.

The pay offered for this position may vary based on several individual factors, including job-related knowledge, skills, and experience. The total compensation package may also include additional components and benefits depending on the specific role. This information will be shared if an employment offer is extended.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Hark's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Hark's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Hark's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.