
Security Engineer I, Application Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Participate in security assessments of client software while collaborating with seasoned engineers.
• Oversee the review of a specific component, module, or system within broader client projects.
• Identify root causes and manage analysis from the discovery of vulnerabilities to client delivery.
• Detect and validate vulnerabilities within application code and systems.
• Clarify exploitation paths, evaluate impact, and develop proof-of-concept code when suitable.
• Create and develop security-testing tools and automation for vulnerability detection and in-depth analysis.
• Analyze software architectures to pinpoint attack surfaces, data flows, trust boundaries, and privilege boundaries.
• Propose tangible security mitigations.
• Convert technical findings into clear, actionable recommendations for engineering teams.
• Justify conclusions with evidence to clients.
• Engage in security research, contribute to open-source tools, share knowledge internally, and produce technical documentation.
• A minimum of 1 year of relevant experience in application security, vulnerability research, security-focused software engineering, or a related field.
• Proven capability in vulnerability discovery, including personally identifying or validating a vulnerability or security weakness.
• Strong skills in code analysis, such as reading unfamiliar code, tracing execution and data flow, spotting flaws, and validating vulnerabilities.
• Proficiency in coding with at least two relevant languages, including Rust, Go, C, C++, Python, JavaScript, or TypeScript.
• Understanding of memory-corruption vulnerabilities and common mitigations, including buffer overflows, use-after-free, stack cookies, ASLR, NX/DEP, CFI, or MTE.
• Familiarity with operating system concepts, IPC, privilege boundaries, and how applications interact with system internals.
• Ability to independently investigate a well-defined problem, debug issues, document evidence, ask targeted questions, and deliver work with project-lead review.
• Excellent written and verbal communication skills, including the ability to explain technical findings and remediation guidance to software engineers, and to collaborate effectively in a distributed team.
• Preferred: Participation in CTFs, published vulnerability research/CVEs/responsible disclosures/bug bounty findings, contributions to open-source security, mobile application security, cloud or infrastructure assessments, Kubernetes, Helm, Terraform, Ansible, kernel code, drivers, reverse engineering, fuzzing, low-level systems work, technical writing, conference presentations, or substantial technical documentation.
• U.S.-based candidates must comply with employment eligibility verification requirements through E-Verify.
• Competitive salary along with performance-based bonuses.
• Comprehensive insurance packages fully paid by the company, covering health, dental, vision, disability, and life.
• A robust 401(k) plan with a 5% match of your base salary.
• 20 days of paid vacation, with the option for more, in accordance with jurisdictional regulations.
• Four months of parental leave.
• $10,000 in relocation assistance for moving to NYC.
• $1,000 Work-from-Home stipend.
• Annual $750 Learning & Development stipend.
• Company-sponsored all-team celebrations, including travel and accommodation.
• Matching for philanthropic contributions up to $2,000 annually.
• A remote-first culture for full-time employees.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.