Source Job

$172,000–$216,000/yr
US Canada Unlimited PTO

  • You will own and drive the AppSec/DevSecOps program roadmap, defining security strategy across the SDLC.
  • You will design and maintain DevSecOps tooling in Kubernetes and GCP, including support for AI/ML workloads.
  • You will lead integration of security into CI/CD pipelines, building secure paths and guardrails that reduce developer friction.

Kubernetes DevSecOps CI/CD Python Cloud Security

20 jobs similar to Staff Application Security Engineer

Jobs ranked by similarity.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

India

  • Integrate and automate security controls into CI/CD pipelines for continuous vulnerability scanning and secure software delivery.
  • Design, implement, and maintain secure Infrastructure as Code across GCP environments, enforcing IAM and network security policies.
  • Drive compliance and continuous auditing, acting as technical point for PCI-DSS and SOC 2 evidence collection.

Zact is a leading fintech innovator specializing in cutting-edge payments apps. They are a remote-first company with a focus on hiring in India, fostering a security-first engineering culture.

$137,000–$160,000/yr
US Unlimited PTO 18w maternity 12w paternity

  • Architect and maintain secure, resilient, and optimized cloud environments primarily in GCP, with AWS and Azure.
  • Partner with Developer Platform and IAM teams to embed security into architecture and identity strategies.
  • Harden cloud platforms against emerging threats, bring a DevOps mindset with Terraform/IaC and Kubernetes, and help secure AI-driven pipelines.

Chainguard is the trusted source for open source software, delivering hardened and secure builds. They are a venture-backed late-stage startup serving Fortune 500 enterprises and global industry leaders.

Mexico

  • Drive security engineering initiatives and embed security across engineering teams.
  • Manage threats and respond to incidents with advanced automation and AI agents.
  • Architect secure solutions for AI/ML workloads and mentor team members.

EarnIn is a pioneer of earned wage access, building products that deliver real-time financial flexibility for those living paycheck to paycheck. They have an experienced leadership team and world-class funding partners, and are growing fast with a healthy core business.

$152,000–$195,000/yr
US Unlimited PTO

  • Design, build, and scale Kubernetes infrastructure for secure, multi-tenant, high-availability applications.
  • Build and operate AI tooling infrastructure, including MCP servers and secure AI access.
  • Optimize CI/CD pipelines, implement progressive delivery, and advance Infrastructure as Code.

SecurityScorecard is the global leader in cybersecurity ratings, rating over 12 million companies across 64 countries. Headquartered in New York, it is recognized as a best workplace and funded by top investors.

$150,000–$195,000/yr
US Unlimited PTO

  • Lead and contribute to projects enhancing security, reliability, release processes, and developer experiences.
  • Collaborate with engineering, IT, and People teams to solve security challenges across infrastructure, CI, and applications.
  • Implement infrastructure-as-code and compliance initiatives, and improve developer tools and workflows.

AllTrails is the app for exploring the outdoors, connecting people to their next adventure. With the world's largest outdoor community and members globally, we lead with values like positivity, innovation, and inclusivity.

$125,000–$152,000/yr
US

  • Bridge the gap between traditional infrastructure security and modern DevSecOps, defining secure-by-design frameworks and implementing high-impact DevSecOps pipelines across multi-cloud environments.
  • Lead critical security reviews for emerging technologies, including artificial intelligence, and act as a collaborative partner to internal teams fostering proactive security and cyber vigilance.
  • Manage security lifecycles within multi-cloud environments, own the end-to-end vulnerability management program, and leverage SIEM platforms for real-time threat intelligence.

NPR is a thriving, mission-driven multimedia organization that produces award-winning news, information, and music programming in partnership with hundreds of independent public radio stations across the nation. They are innovators and leaders in diverse fields, from journalism and digital media to IT and development, committed to building an inclusive workplace where collaboration is essential and diverse voices are heard.

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and advance the S-SDLC program.
  • Mentor engineers on secure coding and career growth.
  • Evaluate and recommend AI-assisted security tooling.

Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.

US

  • Lead the evolution of the software delivery lifecycle by embedding security into every stage of the CI/CD pipeline.
  • Integrate existing automation frameworks with AI-based solutions to improve coverage, reliability, and efficiency.
  • Collaborate with software developers and IT staff to oversee code releases and deployments.

Tier One Technologies provides technology solutions for government clients, focusing on security and compliance. The company sizes are not specified, but the culture emphasizes collaboration and security.

Portugal

  • Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
  • Use your knowledge of security architecture to help engineers build and securely operate products and services from the ground up.
  • Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.

LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity.

US

  • Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
  • Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
  • Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.

Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.

$230,000–$250,000/yr
United States Unlimited PTO 12w maternity 12w paternity

  • Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of AI/ML workloads.
  • Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources.
  • Act as the senior security resource across cloud security and security reviews, mentoring teammates.

SmarterDx is a clinical AI platform that helps health systems capture revenue and improve quality metrics using clinically-validated EHR data. The company is a remote-first team with a small, collaborative engineering culture focused on making healthcare more accurate and effective.

$130,000–$160,000/yr
US Unlimited PTO

  • Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
  • Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
  • Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.

Airship provides a no-code, AI-powered platform for brands like Alaska Airlines and BBC to create personalized cross-channel customer experiences. The company fosters a digital-first, flexible remote culture with a collaborative team across time zones.

US 5w PTO

  • Own key security domains such as vulnerability management, application security, API security, and supply chain security.
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
  • Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.

NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.

$186,000–$256,000/yr
US Unlimited PTO

  • Lead a small, high-leverage team of senior and staff security engineers, setting technical direction and growing talent.
  • Partner with product and executives to deliver AI-first security capabilities and represent security to customers.
  • Turn compliance (ISO 27001, SOC 2) into continuous assurance, protecting customer trust.

Sysdig creates cloud security solutions, including the open standard Falco for threat detection, used by over 60% of the Fortune 500. Recognized as a Best Place to Work and one of Deloitte's fastest-growing companies for the past 5 years, they value diversity and open dialogue.

Germany

  • Design, build, and operate AI security runtime controls across cloud platforms.
  • Develop and maintain security solutions for AI interactions, LLMs, and agent workflows.
  • Act as senior escalation point for complex AI security incidents.

Europe US Unlimited PTO

  • Triage, validate, and remediate security vulnerabilities across products, infrastructure, and internal systems.
  • Develop, maintain, and contribute to internal and open-source security tooling, writing production-grade code.
  • Improve secure development practices through code reviews, threat modeling, and security design reviews.

Tiger Data provides the fastest PostgreSQL platform for transactional, analytical, and agentic workloads. With over 2,000 customers and 3 million active databases, it is a remote-first team backed by $180 million in funding.

Canada

  • Lead a specialized team of security engineers focused on application, cloud, and AI system security.
  • Champion shift-left security practices including threat modeling, secure code review, and developer training.
  • Define cloud security standards and enforce security for AI systems including LLM-based agents.

Acquia empowers ambitious brands to create digital customer experiences using open source Drupal. Headquartered in Boston, MA, it is a Great Place to Work-Certified company and among the world's top software companies.

Ireland

  • Investigate and resolve customer technical issues across cloud security posture management, vulnerability scanning, and threat detection in AWS, Azure, and GCP environments.
  • Troubleshoot cloud connector and integration failures, including IAM, network connectivity, and API authentication issues.
  • Design and implement automation leveraging AI agents to improve triage accuracy and resolution efficiency.

Wiz provides an AI-powered cloud security platform that connects code, cloud, and runtime to secure cloud and AI applications, trusted by over 65% of the Fortune 100. As one of the fastest-growing startups, powered by Google, Wiz has a culture that values world-class talent and encourages creative thinking.

$135,000–$160,000/yr
US

  • Build tools, automation, and infrastructure for scalable adversarial testing of AI systems.
  • Build and maintain realistic security test environments using cloud infrastructure and automation tools like Terraform.
  • Collaborate with red teamers and engineers to reproduce, investigate, and remediate vulnerabilities.

10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They operate in a fast-paced, high-growth startup environment with a collaborative and builder-oriented culture.