Summary
What you’ll impact
The Application Security Engineer at the organization will lead advanced penetration testing engagements across web, mobile, and cloud applications, developing sophisticated attack plans and remediation guidance. The role involves building AI-driven automation workflows, mentoring junior staff, and collaborating with cross‑functional teams to embed security best practices and drive security maturity.
Responsibilities
What you'll do
- Lead and execute advanced penetration testing engagements across various application environments, including web, mobile, and cloud
- Design and implement sophisticated attack strategies to identify vulnerabilities and security gaps
- Develop actionable remediation guidance and collaborate with development teams to improve product security
- Build and operate agentic AI workflows to automate and scale security testing processes
- Assess risks and contribute to key security decision-making processes to ensure products meet high security standards
- Proactively stress-test our ecosystem to identify potential threats before they materialize
- Mentor junior security team members and foster a culture of continuous security improvement
- Participate in security community activities, staying updated on the latest threats and mitigation techniques
- Collaborate with cross-functional teams to embed security best practices into the development lifecycle
Requirements
What you’ll bring
- Bachelor's degree with 7+ years of relevant experience, or Master’s degree with 4+ years, or PhD with 1+ years in application security or related fields
- Proven experience in offensive security, including web applications, mobile applications, networks, and distributed systems
- Deep technical understanding of common vulnerabilities, attack vectors, and remediation strategies
- Hands-on experience working with public cloud platforms such as AWS and GCP
- Proficiency in developing and maintaining custom security tooling using languages like Python or Bash
- Active contributions to the security community through publications, CVEs, open-source projects, or bug bounty recognitions (preferred)
- Experience with development and automation languages such as C++, JavaScript, Python, or Go (preferred)
- Familiarity with large-scale data platforms like Splunk or similar (preferred)
- Ability to build and nurture cross-functional relationships with engineering teams to enhance security maturity
- Excellent communication skills with a track record of mentoring and providing constructive technical feedback