{"schemaVersion":"jobsearcher.job.v1","id":"f736db7367dade5e98363806","url":"https://jobsearcher.com/jobs/f736db7367dade5e98363806","canonicalUrl":"https://jobsearcher.com/jobs/f736db7367dade5e98363806","title":"Lead Application Security Engineer, Code to Cloud","description":"Overview:\n\nAs a Lead Application Security Engineer, Code to Cloud at QXO, you’ll be the recognized subject matter expert for application security across the company and own the engineering behind Code to Cloud: continuous security coverage across QXO’s software delivery lifecycle, from source code through pipeline execution to cloud runtime.\n\nQXO is building a modern cybersecurity function from the ground up, automation-first. This is a large, enterprise-wide program spanning three engineering organizations, and you will run your part of it with limited oversight, defining the standards QXO builds against rather than applying someone else’s. Attackers operate at machine speed, and human-speed review cannot meet that, so we automate first.\n\nQXO is a leading distributor and installer of building products serving an $800 billion market. The company’s mission is to modernize the building products industry through advanced technology and a best-in-class customer experience. QXO is North America’s largest distributor and installer of insulation, the second-largest distributor of roofing products, the second-largest publicly traded distributor of lumber and building materials, and the largest distributor of waterproofing products. The company is targeting $50 billion in annual revenue within the decade through accretive acquisitions and organic growth. For more information, visit QXO.com.\n\nWhat you will do::\nOwn the scanning and posture platform end to end across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, at a false-positive rate engineers trust. Build the automation that routes, deduplicates, and prioritizes findings, with owner resolution, SLA tracking, and closure verification.\nBuild and run policy-based blocking controls in pull requests and CI/CD pipelines, as policy-as-code applied centrally and scoped to repository tiering, so coverage inherits to future repositories. Turn a gate on only when the baseline is triaged and false positives are under bar, and never block a team without a path forward.\nAuthor the application security standards, secure design patterns, and remediation SLAs QXO builds against, own the exception and risk-acceptance workflow, and report on risk reduced rather than finding counts. Make threat modeling repeatable through templates and AI-assisted triage, producing testable requirements.\nSit in architecture and design reviews with principal engineers and reach a decision in the room: where a gateway-validated token stops being sufficient and service identity needs its own mechanism, how object-level authorization survives a list endpoint, and why a service must never take an authorization attribute from its caller. Review third-party integrations before production.\nSet the technical bar for the practice: coach, review, and direct the security work of the champions network and third-party testing partners, and mentor engineers added to the team. Be the person engineering calls, explaining what a finding means and what it does not, so a blocked developer gets an answer the same day.\nOwn security testing of the running application, not just its source, and work with developers to remediate what it finds, verifying on retest. Lead the response when a critical vulnerability or exploit drops.\nLead the security integration of acquired engineering environments, bringing their repositories, pipelines, and cloud accounts under coverage without stalling delivery.\nWhat you will bring::\n8+ years in application security, product security, DevSecOps, or security engineering, most of it hands-on rather than advisory.\nHands-on experience owning an enterprise-scale security program across multiple teams and stakeholder groups with limited oversight, including setting standards others follow and reviewing the work of other engineers.\nDepth in a cloud-native application protection or application security posture platform such as Wiz, Snyk, Prisma Cloud, or Orca. You have written policy and built on its API, not just read dashboards.\nPipeline enforcement you have actually shipped: policy-based blocking in pull requests and CI/CD, security policy-as-code, and the harder part, moving a control from advisory to blocking without an engineering revolt.\nThreat modeling you have run, not just studied. STRIDE or an equivalent applied to real systems, extended with MITRE ATLAS and the LLM risk taxonomies where classical categories fall short on AI-enabled systems.\nArchitecture-level security judgment. You can hold your own with a principal engineer on authorization design in a distributed system: trust boundaries, token validation, service-to-service identity, and object-level access control.\nApproachable, responsive, and constructive under pressure. You can tell a team their launch has a problem without becoming the reason they route around security.\nAn automation-first, AI-forward way of working, and a defensible view on securing AI itself: validating AI-generated code, and agentic risk including prompt injection, tool permissions, and the MCP supply chain.\nDynamic testing of running applications and APIs through DAST tooling, API security testing, or hands-on offensive work, and cloud security depth in a major public cloud, Google Cloud a plus.\nCoding ability in Python, Go, or TypeScript, and writing that is tight, evidence-backed, and defensible when challenged.\n\nEducation & Certifications\n\nBachelor’s in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred. Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect. CSSLP, GWAPT, OSWE, or OSCP a plus.\nWhat you will earn::\nBase pay range: $101,300 - $172,000\nAnnual performance bonus\n401(k) with employer match\nMedical, dental, and vision insurance\nPTO, company holidays, and parental leave\nPaid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.\nPaid training and certifications\nLegal assistance and identity protection\nPet insurance\nEmployee assistance program (EAP)\n\nTo comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.\n\nPlease contact careers@QXO.com if you have any questions related to this job posting.\n\nQXO is an Equal Opportunity Employer. We value diversity and do not discriminate on the basis of race, color, religion, gender or sexual orientation, national origin, age, disability, or any other protected status.\n\nPay Range: USD $101,300.00 - USD $172,000.00 /Yr.","company":"QXO","rawCompany":"qxo","city":"Vancouver","state":"WA","isRemote":false,"isActive":false,"createdAt":"2026-09-24T07:22:55.853Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Application Security Engineer, Code to Cloud","description":"Overview:\n\nAs a Lead Application Security Engineer, Code to Cloud at QXO, you’ll be the recognized subject matter expert for application security across the company and own the engineering behind Code to Cloud: continuous security coverage across QXO’s software delivery lifecycle, from source code through pipeline execution to cloud runtime.\n\nQXO is building a modern cybersecurity function from the ground up, automation-first. This is a large, enterprise-wide program spanning three engineering organizations, and you will run your part of it with limited oversight, defining the standards QXO builds against rather than applying someone else’s. Attackers operate at machine speed, and human-speed review cannot meet that, so we automate first.\n\nQXO is a leading distributor and installer of building products serving an $800 billion market. The company’s mission is to modernize the building products industry through advanced technology and a best-in-class customer experience. QXO is North America’s largest distributor and installer of insulation, the second-largest distributor of roofing products, the second-largest publicly traded distributor of lumber and building materials, and the largest distributor of waterproofing products. The company is targeting $50 billion in annual revenue within the decade through accretive acquisitions and organic growth. For more information, visit QXO.com.\n\nWhat you will do::\nOwn the scanning and posture platform end to end across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, at a false-positive rate engineers trust. Build the automation that routes, deduplicates, and prioritizes findings, with owner resolution, SLA tracking, and closure verification.\nBuild and run policy-based blocking controls in pull requests and CI/CD pipelines, as policy-as-code applied centrally and scoped to repository tiering, so coverage inherits to future repositories. Turn a gate on only when the baseline is triaged and false positives are under bar, and never block a team without a path forward.\nAuthor the application security standards, secure design patterns, and remediation SLAs QXO builds against, own the exception and risk-acceptance workflow, and report on risk reduced rather than finding counts. Make threat modeling repeatable through templates and AI-assisted triage, producing testable requirements.\nSit in architecture and design reviews with principal engineers and reach a decision in the room: where a gateway-validated token stops being sufficient and service identity needs its own mechanism, how object-level authorization survives a list endpoint, and why a service must never take an authorization attribute from its caller. Review third-party integrations before production.\nSet the technical bar for the practice: coach, review, and direct the security work of the champions network and third-party testing partners, and mentor engineers added to the team. Be the person engineering calls, explaining what a finding means and what it does not, so a blocked developer gets an answer the same day.\nOwn security testing of the running application, not just its source, and work with developers to remediate what it finds, verifying on retest. Lead the response when a critical vulnerability or exploit drops.\nLead the security integration of acquired engineering environments, bringing their repositories, pipelines, and cloud accounts under coverage without stalling delivery.\nWhat you will bring::\n8+ years in application security, product security, DevSecOps, or security engineering, most of it hands-on rather than advisory.\nHands-on experience owning an enterprise-scale security program across multiple teams and stakeholder groups with limited oversight, including setting standards others follow and reviewing the work of other engineers.\nDepth in a cloud-native application protection or application security posture platform such as Wiz, Snyk, Prisma Cloud, or Orca. You have written policy and built on its API, not just read dashboards.\nPipeline enforcement you have actually shipped: policy-based blocking in pull requests and CI/CD, security policy-as-code, and the harder part, moving a control from advisory to blocking without an engineering revolt.\nThreat modeling you have run, not just studied. STRIDE or an equivalent applied to real systems, extended with MITRE ATLAS and the LLM risk taxonomies where classical categories fall short on AI-enabled systems.\nArchitecture-level security judgment. You can hold your own with a principal engineer on authorization design in a distributed system: trust boundaries, token validation, service-to-service identity, and object-level access control.\nApproachable, responsive, and constructive under pressure. You can tell a team their launch has a problem without becoming the reason they route around security.\nAn automation-first, AI-forward way of working, and a defensible view on securing AI itself: validating AI-generated code, and agentic risk including prompt injection, tool permissions, and the MCP supply chain.\nDynamic testing of running applications and APIs through DAST tooling, API security testing, or hands-on offensive work, and cloud security depth in a major public cloud, Google Cloud a plus.\nCoding ability in Python, Go, or TypeScript, and writing that is tight, evidence-backed, and defensible when challenged.\n\nEducation & Certifications\n\nBachelor’s in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred. Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect. CSSLP, GWAPT, OSWE, or OSCP a plus.\nWhat you will earn::\nBase pay range: $101,300 - $172,000\nAnnual performance bonus\n401(k) with employer match\nMedical, dental, and vision insurance\nPTO, company holidays, and parental leave\nPaid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.\nPaid training and certifications\nLegal assistance and identity protection\nPet insurance\nEmployee assistance program (EAP)\n\nTo comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.\n\nPlease contact careers@QXO.com if you have any questions related to this job posting.\n\nQXO is an Equal Opportunity Employer. We value diversity and do not discriminate on the basis of race, color, religion, gender or sexual orientation, national origin, age, disability, or any other protected status.\n\nPay Range: USD $101,300.00 - USD $172,000.00 /Yr.","datePosted":"2026-09-24T07:22:55.853Z","dateModified":"2026-09-24T07:22:55.853Z","hiringOrganization":{"@type":"Organization","name":"QXO","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Vancouver","addressRegion":"WA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"f736db7367dade5e98363806"},"url":"https://jobsearcher.com/jobs/f736db7367dade5e98363806"}}