Skip to content

Open nowPosted 7 days agoWe saw it 59 min after it went up

Sr. Security Engineer

Lucid Software30 open roles

Where
Salt Lake City, UT
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. Security EngineerLucid Software · Salt Lake City, UT
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Lucid Software's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Lucid Software postings stay open a median of 22 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.1%30 days
This job: posted 7 days ago

Lucid Software median: 22 days open

The posting

Lucid Software is the leader in AI-driven work acceleration, helping teams see and build the future by turning ideas into reality. Its products include the Lucid Visual Collaboration Suite (Lucidchart and Lucidspark) and airfocus. The Lucid Visual Collaboration Suite, combined with powerful accelerators for cloud and process transformation, empowers organizations to streamline work, foster alignment, and drive business transformation at scale. We hold true to our core values: innovation in everything we do, passion & excellence in every area, individual empowerment, initiative and ownership, and teamwork over ego. At Lucid, we value diverse perspectives and are dedicated to creating an environment and culture that is respectful and inclusive for everyone. Lucid is a hybrid workplace. We promote a healthy work-life balance by allowing employees to work remotely, from one of our offices, or a combination of the two depending on the needs of the role and team.

As a Senior Application Security Engineer at Lucid, you will be a trusted security partner embedded in the heart of our development lifecycle. You'll work closely with engineering, product, and corporate teams to build security in from the start.

Lucid's customers trust us with their data, and that trust is foundational to our mission. A successful Senior Application Security Engineer combines deep technical knowledge with strong relationship-building skills, enabling product teams to move fast without taking on undue risk.

Responsibilities:

  • Conduct thorough security architecture and design reviews for new and evolving product features, surfacing risk early and recommending practical mitigations.
  • Drive a risk-based approach to application security, helping teams understand and prioritize vulnerabilities by business impact.
  • Serve as a subject matter expert on application security topics for product, engineering, legal, and leadership stakeholders.
  • Mentor engineers across the organization on secure development practices, fostering a culture where security is everyone's responsibility.
  • Build and maintain strong, collaborative partnerships with product and engineering teams, serving as their primary security resource and advocate throughout the software development lifecycle.
  • Mature Lucid's Secure Software Development Lifecycle (SSDLC), including secure coding standards, security requirements, and developer security education.
  • Ensure AI tools and processes are implemented within acceptable risk limits.
  • Lead product design reviews to ensure security considerations are inherent in feature design.
  • Develop and maintain scalable security tooling and automation to integrate security controls into CI/CD pipelines with a focus on reducing risk over implementing tools.
  • Lead and train engineers in Lucid’s security champions program.

Requirements:

  • 5+ combined years of experience in software engineering, application security, product security, or a closely related field within a SaaS environment.
  • Proven track record of building trusted, effective relationships with product and engineering teams.
  • Experience securing web applications built on modern frameworks and cloud-native architectures (particularly AWS).
  • White-box penetration testing experience.
  • Strong understanding of SSDLC principles and experience implementing or maturing secure development programs.
  • Ability to conduct meaningful security architecture and design reviews, with a focus on identifying risk early in the development process.
  • Solid understanding of common application vulnerabilities and attack techniques (OWASP Top 10, API security, authentication/authorization flaws, etc.).
  • Experience integrating security tooling into modern CI/CD pipelines.
  • Risk-focused mindset: able to articulate security risk in business terms and help teams make informed, pragmatic decisions while avoiding security theater.
  • Familiarity with AI security risks and emerging attack surfaces, including securing agentic systems, MCP, and LLM-powered workflows against new and evolving threats.
  • Strong written and verbal communication skills; equally comfortable in a design review with engineers and a risk conversation with leadership.

Preferred Qualifications:

  • Development experience in modern tech stacks.
  • Practical knowledge of relevant security frameworks and compliance standards (e.g., OWASP ASVS, NIST 800-53, SOC 2, GDPR).
  • Relevant certifications such as OSCP, BSCP, GWEB, PNPT, or similar hands-on security-focused certifications.
  • Experience with bug bounty program management.
  • Bachelor's degree in Computer Science, Information Security, or a related field.

#LI-DA1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Lucid Software's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Lucid Software's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Lucid Software's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.