{"schemaVersion":"jobsearcher.job.v1","id":"5cc9b07d368c0a16cd7a6b90","url":"https://jobsearcher.com/jobs/5cc9b07d368c0a16cd7a6b90","canonicalUrl":"https://jobsearcher.com/jobs/5cc9b07d368c0a16cd7a6b90","title":"Application Security - Vulnerability Discovery","description":"Job Information\nDate Opened\n07/16/2026\nJob Type\nFull time\nRemote Job\nIndustry\nTechnology\nThis is a remote position.\nProduct Security Engineer CW Job Description\n\nThis document outlines the job description for an Application Security Engineer (Contractor) that will be partnering with the Product Security organization\n\nTeam Description\n\nAs part of the Product Security Engineering team, you’ll be working to reduce overall security risk across Dropbox. We partner with engineering and product teams during each point of the software development lifecycle (SDLC) and help drive broader security initiatives across Dropbox.\n\nProduct Security Engineers provide security impact by developing secure-by-default libraries and frameworks that teams across Dropbox can frictionlessly integrate into their products. They also offer their expertise on security matters through documentation and educational initiatives.\n\nResponsibilities\n\nTriage, validate, and prioritize security vulnerabilities identified through manual reviews, automated tooling, bug bounty reports, and AI-assisted security analysis platforms.\n\nParticipate in on-call rotation to support security incident triage, perform code reviews, and address security questions.\n\nPartner closely with engineering teams to drive remediation efforts, provide actionable guidance, and ensure timely closure of security findings based on risk and severity.\n\nReview security-related pull requests and code changes, providing guidance on secure implementation patterns and identifying potential vulnerabilities before production deployment.\n\nAnalyze findings generated by AI-powered security agents and automation platforms, validate results, reduce false positives, and help drive remediation workflows across engineering teams.\n\nCollaborate with Product Security Architecture and development teams to improve vulnerability detection, prioritization, and remediation processes.\n\nSupport security incident investigations and root cause analysis when vulnerabilities or application security issues are discovered.\n\nDevelop security tooling, automation, and workflows that improve security coverage and reduce manual effort for security reviews and vulnerability management.\n\nAdminister and manage vulnerability scanning tools (e.g., Tenable or similar)\n\nConfigure, optimize, and maintain scanning tools, policies, and schedules\n\nTrack and report on remediation progress, security metrics, and risk reduction initiatives across assigned engineering organizations.\n\nContribute to security documentation, best practices, and developer education efforts to improve secure coding practices across Dropbox.\n\nRequirements\n\nAvailable to work until 11:00AM Pacific Standard Time (PST).\n\n3+ years experience in application security engineering\n\nStrong communication skills and relationship building skills\n\nExperience in building and scaling the Secure Development Lifecycle\n\nExperience with handling vulnerability, and bug bounty reports\n\nExperience partnering with cross-functional engineering and product teams\n\nExperience triaging, validating, and prioritizing security vulnerabilities from static analysis, dynamic analysis, dependency scanning, penetration testing, or bug bounty programs.\n\nExperience partnering with software engineering teams to drive remediation and risk reduction efforts.\n\nStrong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.).\n\nExperience reviewing source code and identifying security vulnerabilities in modern programming languages and frameworks.\n\nFamiliarity with security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, and vulnerability management platforms.\n\nExperience working with cloud-native architectures and public cloud environments (AWS preferred).\n\nAbility to evaluate security findings, distinguish signal from noise, and communicate risk-based remediation recommendations.\n\nFamiliarity with AI-assisted development workflows, AI-powered security tooling, or LLM-based security use cases is a plus.","company":"Srmtechnologies","rawCompany":"srmtechnologies","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-03T22:52:34.950Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security - Vulnerability Discovery","description":"Job Information\nDate Opened\n07/16/2026\nJob Type\nFull time\nRemote Job\nIndustry\nTechnology\nThis is a remote position.\nProduct Security Engineer CW Job Description\n\nThis document outlines the job description for an Application Security Engineer (Contractor) that will be partnering with the Product Security organization\n\nTeam Description\n\nAs part of the Product Security Engineering team, you’ll be working to reduce overall security risk across Dropbox. We partner with engineering and product teams during each point of the software development lifecycle (SDLC) and help drive broader security initiatives across Dropbox.\n\nProduct Security Engineers provide security impact by developing secure-by-default libraries and frameworks that teams across Dropbox can frictionlessly integrate into their products. They also offer their expertise on security matters through documentation and educational initiatives.\n\nResponsibilities\n\nTriage, validate, and prioritize security vulnerabilities identified through manual reviews, automated tooling, bug bounty reports, and AI-assisted security analysis platforms.\n\nParticipate in on-call rotation to support security incident triage, perform code reviews, and address security questions.\n\nPartner closely with engineering teams to drive remediation efforts, provide actionable guidance, and ensure timely closure of security findings based on risk and severity.\n\nReview security-related pull requests and code changes, providing guidance on secure implementation patterns and identifying potential vulnerabilities before production deployment.\n\nAnalyze findings generated by AI-powered security agents and automation platforms, validate results, reduce false positives, and help drive remediation workflows across engineering teams.\n\nCollaborate with Product Security Architecture and development teams to improve vulnerability detection, prioritization, and remediation processes.\n\nSupport security incident investigations and root cause analysis when vulnerabilities or application security issues are discovered.\n\nDevelop security tooling, automation, and workflows that improve security coverage and reduce manual effort for security reviews and vulnerability management.\n\nAdminister and manage vulnerability scanning tools (e.g., Tenable or similar)\n\nConfigure, optimize, and maintain scanning tools, policies, and schedules\n\nTrack and report on remediation progress, security metrics, and risk reduction initiatives across assigned engineering organizations.\n\nContribute to security documentation, best practices, and developer education efforts to improve secure coding practices across Dropbox.\n\nRequirements\n\nAvailable to work until 11:00AM Pacific Standard Time (PST).\n\n3+ years experience in application security engineering\n\nStrong communication skills and relationship building skills\n\nExperience in building and scaling the Secure Development Lifecycle\n\nExperience with handling vulnerability, and bug bounty reports\n\nExperience partnering with cross-functional engineering and product teams\n\nExperience triaging, validating, and prioritizing security vulnerabilities from static analysis, dynamic analysis, dependency scanning, penetration testing, or bug bounty programs.\n\nExperience partnering with software engineering teams to drive remediation and risk reduction efforts.\n\nStrong understanding of common application security vulnerabilities (OWASP Top 10, API Security, authentication, authorization, secrets management, cryptography, etc.).\n\nExperience reviewing source code and identifying security vulnerabilities in modern programming languages and frameworks.\n\nFamiliarity with security tooling such as SAST, DAST, SCA, IaC scanning, secrets detection, and vulnerability management platforms.\n\nExperience working with cloud-native architectures and public cloud environments (AWS preferred).\n\nAbility to evaluate security findings, distinguish signal from noise, and communicate risk-based remediation recommendations.\n\nFamiliarity with AI-assisted development workflows, AI-powered security tooling, or LLM-based security use cases is a plus.","datePosted":"2026-08-03T22:52:34.950Z","dateModified":"2026-08-03T22:52:34.950Z","hiringOrganization":{"@type":"Organization","name":"Srmtechnologies","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5cc9b07d368c0a16cd7a6b90"},"url":"https://jobsearcher.com/jobs/5cc9b07d368c0a16cd7a6b90"}}