Staff Application Security Engineer
Censys $172K - $233K/year Posted 3 days ago100% remote US only US (remote)About The RoleCompany BackgroundCensys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.At Censys, we’re on a mission to provide best in class internet visibility and intelligence to the global security community. Our platform helps security teams uncover hidden threats, gain actionable insights, and build proactive defense strategies. Trusted by organizations worldwide, Censys cuts through the noise to surface the most critical risks, enabling teams to respond faster, and stay ahead of attackers. We’re constantly pushing the boundaries of what’s possible to help our customers see and secure the internet more clearly than ever before.Role SummaryCensys is seeking a Staff Application Security Engineer to join our Infrastructure and Operations Platform (SRE) team. In this role, you’ll own the application security strategy for how Censys builds and ships software — designing the secure paths, guardrails, and automation that let our engineers develop and deploy quickly, confidently, and securely. You’ll set technical direction across the software lifecycle, from infrastructure-as-code and container security to secure deployment workflows and the security of our AI/ML-enabled services. As a security company, we hold ourselves to the standard we help our customers achieve; this role is central to making that real. We expect all of our employees to consider customer happiness as our primary goal and to come to work every day eager to learn and educate, helping to make us a better organization every day.What You’ll DoOwn and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gatesDesign, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloadsLead the integration of security into CI/CD pipelines — code scanning, secret detection, software composition analysis, and infrastructure policy enforcement — partnering with engineering teams to adopt them without frictionDeliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organizationSet the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance trackingPartner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracyProvide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teamsParticipate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readinessWhat You’ll Bring10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teamsDeep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane)Strong experience with Application Security tooling — dependency scanning, static analysis, and policy enforcement — integrated into CI/CD pipelines such as GitHub Actions and ArgoCD, and the ability to bridge engineering practices with Security OperationsStrong understanding of attacker tactics, techniques, and procedures (TTPs), and familiarity with frameworks like MITRE ATT&CKStrong grasp of cloud services (GCP preferred), especially securing data pipelines, model hosting endpoints, and related infrastructureProficiency with Infrastructure-as-Code (Terraform, Crossplane, or similar) and security scanning for cloud resourcesProficiency with scripting and automation (e.g., Python, Bash)The ability to thoughtfully participate in technical discussions and drive towards data-driven decisions amidst ambiguity and competing prioritiesStrong communication skills and empathy for developer needs, with a demonstrated ability to embed secure practices without creating frictionWhat Sets You ApartExperience building or scaling an AppSec or DevSecOps program from early maturity, including establishing paved roads and measuring adoptionFamiliarity with commercial security platforms such as Orca Security (CNAPP/cloud security posture) and Aikido Security (application security scanning) is a plusExperience securing ML toolchains (e.g., TensorFlow, PyTorch) and familiarity with AI-specific threats such as data leakage, model inversion, prompt injection, and adversarial inputsHands-on experience integrating and managing Web Application Firewalls (WAF), anti-DDoS systems, and edge protection technologiesFamiliarity with monitoring and observability systems (e.g., Prometheus, Grafana, OpenTelemetry) with a focus on detecting security anomaliesFamiliarity with AI governance and compliance standards (e.g., EU AI Act, NIST AI Risk Management Framework)Strong interest in harnessing AI and LLM tools as a force multiplier — using them to code smarter, iterate faster, boosting productivity and enhancing product capabilitiesBenefitsCensys offers a competitive benefits package to employees, including equity, health, dental & vision coverage, retirement with company contribution, parental leave, mental health & wellness benefits, flexible PTO, and a professional development stipend.SkillsSecurity Python Kubernetes GCP Terraform ArgoCD GitHub Actions AppSec DevSecOps Threat Modeling SOC 2How to applyApply directly on the employer's apply-click#track" data-apply-click-url-value="/jobs/339-staff-application-security-engineer/apply_clicks" data-apply-click-placement-value="prose" data-apply-click-target-value="url" data-apply-click-token-value="eyJfcmFpbHMiOnsiZGF0YSI6eyJqIjozMzksIm4iOiJUcHExRWVBODM2V1JlSko4IiwidCI6MTc4NjExODIwMjI3NX0sImV4cCI6IjIwMjYtMDgtMDhUMDM6NTY6NDIuMjc0WiIsInB1ciI6ImFwcGx5X2NsaWNrIn19--6eba4204f19e0154e278ebb7cb628856f868aa81" href="https://job-boards.greenhouse.io/censys/jobs/8649187002">application page. Your application goes straight to them.Republished listingThis opportunity was discovered on Censys's public careers page and is republished here for discovery purposes. Applications are handled by the employer.Censys team? Claim this listing or ask us to remove it.ApplyApply for this roleYou'll be taken to the employer's own application page.apply-click#track" data-apply-click-url-value="/jobs/339-staff-application-security-engineer/apply_clicks" data-apply-click-placement-value="card" data-apply-click-target-value="url" data-apply-click-token-value="eyJfcmFpbHMiOnsiZGF0YSI6eyJqIjozMzksIm4iOiJUcHExRWVBODM2V1JlSko4IiwidCI6MTc4NjExODIwMjI3NX0sImV4cCI6IjIwMjYtMDgtMDhUMDM6NTY6NDIuMjc0WiIsInB1ciI6ImFwcGx5X2NsaWNrIn19--6eba4204f19e0154e278ebb7cb628856f868aa81" href="https://job-boards.greenhouse.io/censys/jobs/8649187002">Apply nowJob OverviewSalary $172K - $233K/yearLocation Remote US only US (remote)Type Full timeLevel LeadPosted Aug 5, 2026CensysView company & all rolesCurated by ForcepullThis role was curated by the Forcepull team. We hand-picked it because we think it's a great opportunity from a company we respect.