JOBSEARCHER

Senior Application Security Engineer

Overview In this role you will shape and lead an offensive security practice, performing red team engagements and partnering with the blue team to drive purple team outcomes. You will educate developers on secure coding and remediation, and help weave security into the SDLC. The position focuses on advancing attack simulation, detection, and response capabilities while aligning with engineering and business goals. You will work across security, engineering, and product teams to strengthen defenses and reduce risk, using AI-enabled techniques to keep pace with evolving threats. Compensation / Benefitsremote work possiblebonus incentivehealth benefits401K programother employee perks ResponsibilitiesPlan and lead Red Team engagements against applications and infrastructure using offensive testing techniquesCollaborate with Blue Team to improve detections and defenses in real timeAugment offensive methods with AI/LLM tooling for reconnaissance, payload generation, and testingManage the bug bounty program end to end, including triage and remediation guidanceIdentify, triage, and drive remediation of vulnerabilities through manual testing and exploitationLead threat modeling and risk assessments for new and existing applicationsCollaborate with incident response to scope and understand attacker activityHelp define secure development practices and integrate security checks into CI/CDPerform and lead security reviews of critical code changes and PRsAdvise on secure system and application design with engineering and architecture teamsMentor junior security engineers and developers on offensive techniques and secure codingCollaborate with product, engineering, DevOps, and compliance teamsMaintain up-to-date knowledge of offensive techniques, threats, and AI impactsLeverage security tooling (SAST, SCA, DAST, IAST) to support offensive and defensive work Key requirementsExperience leading or performing offensive security work (web app pen testing/Red Team engagements)Hands-on experience with AI/LLM tools for offensive securityProficiency in one modern programming language (preferably Java) and code review ability across major languagesStrong analytical and risk-based security mindsetAdvanced user of Burp Suite Pro; ability to develop/customize extensions in Java or Python is a bonusExcellent communication and cross-functional collaboration skillscommunicationcollaborationmentorshipweb application penetration testingRed Team engagementsAI/LLM tooling for security testing