Skip to content

Open nowPosted 5 hours agoWe saw it 85 min after it went up

Lead Application Security Engineer

Panthalassa45 open roles

Where
Portland, OR
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowLead Application Security EngineerPanthalassa · Portland, OR
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Panthalassa's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Panthalassa postings stay open a median of 32 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 5 hours ago

Panthalassa median: 32 days open

The posting

About the Company

We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on capturing civilizational levels of ultra-low-cost renewable energy for applications including computing and affordable renewable fuels delivered to shore.

The company is a public benefit corporation headquartered in Portland, Oregon, and backed by leading venture capitalists, philanthropic investors, university endowments, and private investment offices. We operate as an idea meritocracy in which the best ideas change the company’s direction on a regular basis.

Our staff have worked at organizations such as SpaceX, Blue Origin, Boeing, Tesla, Apple, Virgin Orbit, Astra, Google, Amazon, Microsoft, New Relic, Bridgewater, Raytheon, Disney Imagineering, and the US Army and Air Force, as well as research universities, startups, and small companies across a range of industries.

About the Job

Our core technology is the node, a device that produces energy in the ocean’s harshest conditions for years at a time without human maintenance or intervention.

As a Lead Application Security Engineer, you will play a key role in advancing Panthalassa’s application security capabilities, partnering closely with the Director of Information Security and software engineering teams. You will bring broad application security and software engineering expertise, strong technical judgment, and the ability to quickly understand unfamiliar languages, frameworks, and architectures. Candidates should possess broad application security and software engineering skills, and be able to quickly come up to speed with languages and frameworks with which they have not previously worked.

Candidates should have strong interpersonal skills and be able to thrive in a creative, scrappy, and collaborative environment in which the best ideas change the company’s direction on a regular basis.

Responsibilities

  • Assist the Head of Information Security with building out the AppSec function at Panthalassa.
  • Conduct code and service architecture reviews to provide security guidance.
  • Lead engineers in threat modelling applications and services.
  • Work with the Head of Information Security to define culturally useful software security metrics.
  • Assist in interviewing and onboarding of other Security personnel.
  • Assist with incident response and handling now while we grow, and provide escalation support for incidents later as we have grown.
  • Integrate, maintain, and automate security scanning tools (SAST, DAST, SCA, and secrets management) directly into our CI/CD pipelines.
  • Build and integrate agentic security tools for Panthalassa needs.
  • Conduct hands-on threat modeling and architectural design reviews for new features and applications before code is written.
  • Perform manual and automated secure code reviews as well as targeted penetration testing on web and mobile applications.
  • Help manage the company’s external Vulnerability Disclosure or Bug Bounty programs and translate regulatory compliance requirements into practical engineering tasks.

Required Qualifications

  • 6+ years of experience with Application Security processes.
  • 2+ years of experience as a Team Lead or Manager of an Application Security team.
  • Both broad in general and deep in places Application Security foundational knowledge.
  • Experience with using AI systems and agents for security outcomes in a professional capacity.
  • Deep understanding of the OWASP Top 10, CWE Top 25, and secure design patterns.
  • Hands-on experience with industry-standard security tools (e.g. Snyk, GitHub Advanced Security, Burp Suite, Fortify).
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience.

Desired Qualifications

  • Experience with software development work related to mechanical engineering environments.
  • Familiarity with cloud platforms (AWS, Azure, or GCP) and modern infrastructure tools like Docker, Kubernetes, and Infrastructure as Code (IaC).

The above qualifications are desired, not required. We encourage you to apply if you are a strong candidate with only some of the desired skills and experience listed.

Additional Requirements

  • Travel to conferences, vendors and test sites as needed.
  • Intermittently able to work longer hours and weekends to support critical needs. While we expect a lot of each other, we also offer a high degree of autonomy and work-life balance, including flexible PTO and flexible working hours.

Compensation and Benefits

If hired for this full-time role, you will receive:

  • Cash compensation of $200,000 - $260,000.
  • Equity in the company. We’re all owners and if we’re successful, this equity should be far and away the most valuable component of your compensation.
  • A benefits package that helps you take care of yourself and your family, including: Flexible paid time off Health insurance (the company pays 100% of gold-level PPO plan for full-time employees, their partners, and dependents) Dental insurance (the company pays 100% for full-time employees, their partners, and dependents) Vision insurance (the company pays 100% for full-time employees, their partners, and dependents) Disability insurance (the company pays 100% for a policy to provide long-term financial support if you become disabled) Ability to contribute to tax-advantaged accounts, including 401(k), health FSA, and dependent care FSA
  • Relocation assistance to facilitate your move to Portland (if needed).

Location

This is an on-site position. Our offices, lab, and shop are located in Portland, Oregon.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Panthalassa's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Panthalassa's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Panthalassa's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.