
Staff Application Security Engineer
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in United States, +1 more state.
β’ Take ownership of the AppSec/DevSecOps program roadmap within engineering, establishing the strategy for incorporating security into the SDLC through shift-left practices, paved roads, and automation instead of barriers.
β’ Design, develop, and sustain DevSecOps tools within Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads.
β’ Spearhead the integration of security into CI/CD pipelines β encompassing code scanning, secret detection, software composition analysis, and infrastructure policy enforcement β collaborating with engineering teams to ensure seamless adoption.
β’ Provide functionalities such as fortified service templates, secure service catalogs, and guardrails that alleviate developer cognitive load and minimize risk throughout the organization.
β’ Define the security architecture for AI/ML workflows, instituting controls around model training, deployment, and inference pipelines, which include access control, artifact validation, input/output sanitization, and model provenance tracking.
β’ Collaborate with CorpSec on organizational security and compliance efforts, overseeing the engineering aspect of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as enhancing tooling related to BCDR, infrastructure policies, and service inventory accuracy.
β’ Offer technical leadership and mentorship, elevating the security standards through design reviews, threat modeling, and practical guidance to engineers across all teams.
β’ Engage in a shared on-call rotation with the Infrastructure and SRE teams, ensuring production uptime and readiness for security incident response.
β’ Over 10 years of experience in Security Engineering, DevSecOps, SRE, or similar roles.
β’ Extensive expertise in securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane).
β’ Significant experience with Application Security tools β dependency scanning, static analysis, and policy enforcement β integrated into CI/CD pipelines such as GitHub Actions and ArgoCD.
β’ Strong understanding of attacker tactics, techniques, and procedures (TTPs), along with familiarity with frameworks like MITRE ATT&CK.
β’ Solid knowledge of cloud services (preferably GCP), particularly in securing data pipelines, model hosting endpoints, and associated infrastructure.
β’ Proficient in Infrastructure-as-Code (Terraform, Crossplane, or comparable) and security scanning for cloud resources.
β’ Skilled in scripting and automation (e.g., Python, Bash).
β’ Excellent communication skills and an understanding of developer needs, with a proven ability to integrate secure practices without causing friction.
β’ Equity
β’ Health, dental & vision coverage
β’ Retirement with company contribution
β’ Parental leave
β’ Mental health & wellness benefits
β’ Flexible PTO
β’ Professional development stipend
β’ Sales incentive pay for sales roles
β’ Annual bonus plan for eligible non-sales roles
Henkel
Pepperl+Fuchs Group
Win Systems
Intel Corporation
Get handpicked remote jobs straight to your inbox weekly.