Skip to content

Open nowPosted 13 hours ago

Staff Application & Product Security Engineer

Jobgether4,318 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Application & Product Security EngineerJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 5 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 13 hours ago

Jobgether median: 5 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Application & Product Security Engineer based in United States.

This Staff-level individual contributor role owns application and product security across both SaaS and customer-hosted products. You will shape how security is embedded throughout the software development lifecycle, from architecture and threat modeling through release and remediation. The role combines hands-on engineering with program ownership, allowing you to establish standards, build automated guardrails, and influence security decisions across engineering teams. You will partner closely with Engineering, Product, Architecture, Cloud Security, and executive leadership to strengthen the security posture of shipped products. A major focus will be vulnerability management, secure development practices, customer-facing product security, and security enablement for developers. You will also lead emerging AI security efforts, establishing practical controls for LLM-enabled features, AI agents, and AI-assisted development workflows. This is an opportunity to make high-impact technical decisions while creating scalable security programs, automation, and processes that support a growing product organization.

Accountabilities:

  • Own and continuously mature the secure software development lifecycle, including security requirements, threat modeling, design reviews, and security controls for high-risk product changes, APIs, and integrations.
  • Run and optimize SAST, SCA, secrets detection, container, and infrastructure-as-code scanning across development and CI/CD environments.
  • Build reusable secure patterns, reference implementations, and policy-as-code controls that make secure development practices easier for engineering teams to adopt.
  • Lead developer security enablement through Security Champions programs, training campaigns, remediation guidance, office hours, and self-service security capabilities.
  • Manage application and product vulnerabilities through risk-based triage, remediation SLAs, escalations, exceptions, exploit reproduction, patch validation, and release verification.
  • Own the penetration testing program, including scoping third-party engagements, performing targeted testing, coordinating remediation, and validating findings through retesting.
  • Manage the Vulnerability Disclosure Program and coordinate communications with external researchers, customers, and other stakeholders through coordinated disclosure processes.
  • Coordinate the CVE lifecycle for products and support product-security incident response activities.
  • Own application and product-security controls within the NIST CSF 2.0 program, tracking maturity, closing gaps, and producing audit evidence.
  • Establish and maintain the security posture of products across SaaS and customer-hosted environments, including secure defaults, authentication, session controls, RBAC, tenant isolation, administrative access, configuration security, and hardening guidance.
  • Own the Product Security Roadmap in partnership with Product Management, Technology leadership, and Architecture, ensuring priority security capabilities are incorporated into product development.
  • Serve as the technical owner for customer-facing product security, including reviewing vulnerability scans and penetration-test reports, responding to security RFIs and enhancement requests, and preparing security advisories, release notes, and hardening documentation.
  • Lead threat modeling and security reviews for LLM-enabled product features, AI agents, and AI-assisted development workflows.
  • Develop security controls and secure patterns addressing prompt injection, sensitive data exposure, insecure output handling, excessive agency, insecure tool integrations, and AI supply-chain risks.
  • Apply and operationalize relevant AI security frameworks and guidance, including the OWASP Top 10 for LLM Applications and the NIST AI Risk Management Framework.
  • 6+ years of experience in application security, product security, or secure software engineering, including experience building or maturing an AppSec program across multiple engineering teams.
  • Strong software development capabilities in an object-oriented programming language, with Java experience preferred; ability to read, debug, and write production-quality code and work across languages such as TypeScript, Python, or Go.
  • Deep understanding of modern application attack surfaces, including authentication, authorization, API security, business-logic vulnerabilities, and contemporary service architectures.
  • Hands-on experience integrating and tuning SAST, SCA, and secrets scanning within GitHub and CI/CD pipelines.
  • Demonstrated ability to reproduce security exploits against running applications, validate patches, and translate technical findings into actionable guidance for both researchers and customers.
  • Experience coordinating vulnerability disclosure with external security researchers and customers, including managing disclosure timelines and driving CVEs through publication.
  • Experience securing shipped software with an established customer base, including secure defaults, hardening guidance, customer advisories, security release notes, and responses to customer scan reports or security RFIs.
  • Practical experience with threat modeling, architecture and design reviews, manual security testing, and direct collaboration with developers throughout remediation.
  • Strong communication skills and the ability to translate complex technical risks into clear engineering guidance for developers and concise risk assessments for executives.
  • Confidence making and defending release-gating security decisions when risk levels warrant escalation.
  • Experience with AI application security, AI agents, or AI-assisted development tools is preferred.
  • Familiarity with SBOM standards such as CycloneDX or SPDX, VEX, artifact signing, and SLSA is a plus.
  • Experience with AWS, Kubernetes/EKS, Terraform, or Jenkins is beneficial.
  • Familiarity with security tools such as Snyk, GitHub Advanced Security, Semgrep, and Burp Suite is preferred.
  • Knowledge of NIST CSF 2.0, OWASP SAMM/ASVS, NIST SSDF, and security audit frameworks such as SOC 2 or ISO 27001 is advantageous.
  • Security certifications such as CSSLP, OSWE, GWAPT, AWS Security, or comparable credentials are a plus.
  • Experience with enterprise software supporting both SaaS and customer-hosted deployment models, including SSO/SAML, RBAC, multi-tenant isolation, MFT/EDI, or other B2B integration products, is beneficial.
  • $160,000–$180,000 base compensation plus bonus opportunity.
  • Healthcare, dental, and vision coverage.
  • Flexible paid time off.
  • Culture focused on support and sustainable work-life balance.
  • 401(k) with company match.
  • Flexible Spending Account (FSA) and Health Savings Account (HSA) options.
  • Employee Assistance Program.
  • Paid parental leave.
  • Remote work environment.
  • Opportunity to contribute to products serving more than 4,000 clients with a 99% retention rate.
  • Accelerated opportunities for title and salary growth.
  • Energetic and collaborative work environment.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.