Senior Application Security & DevSecOps Engineer
Listed on 2026-07-13
-
Software Development
Location: (On-site / Hybrid / Remote – NY, Bay Area, Chicago, Greenville)
Department: Technology
The Role
This is a hands‑on Application Security role, not a generalist security position. As Senior Application Security & Dev Sec Ops Engineer
, you will own the security of our web and mobile applications and the APIs behind them — finding the vulnerabilities before anyone else does, running our offensive testing and bug bounty programs, and building security into the pipelines that ship our code.
You’ll work close to the code. Our stack is heavily automated and developer‑centric: a custom DSL layer governs how code reaches production, translating into Kubernetes and Terraform deployment tasks, and our backend leans on Kotlin and Gradle. You should be able to read and reason about production code, write your own tooling, and own the security of the build and release process end to end — not hand the hard parts to Dev Ops.
If you think like an attacker, are fluent in mobile and API internals, and want to own App Sec for products that millions of people use, this role is for you.
What You'll Do Application Security (core)- Lead secure code review and threat modeling for web, mobile, and API surfaces, and drive secure‑by‑design practices with engineering teams.
- Own the application vulnerability lifecycle — discovery, triage, severity, remediation guidance, and verification — and partner with engineers on durable fixes, not just findings.
- Build internal App Sec tooling and lightweight security libraries that make the secure path the easy path for developers.
- Own security for our iOS and Android apps: secure local storage (Keychain / Keystore), certificate pinning, jailbreak/root and tampering detection, anti‑reverse‑engineering, and secure app‑to‑API communication.
- Assess apps against OWASP MASVS / MASTG, and review third‑party SDKs and dependencies for risk.
- Perform mobile‑focused testing with tooling such as Frida, objection, MobSF, Burp Suite, and static/dynamic RE tools.
- Run internal penetration tests and red‑team‑style assessments against our apps, APIs, and supporting services.
- Validate and weaponize findings to demonstrate real impact, then drive them to resolution.
- Pressure‑test authentication, authorization, session handling, and business‑logic flows (OAuth/OIDC, GraphQL/REST, IDOR, privilege escalation).
- Own and operate our bug bounty program (e.g., Hacker One / Bugcrowd): scope definition, researcher communication, triage, deduplication, severity, and payout coordination.
- Close the loop by feeding bounty findings back into secure code review, threat models, and CI/CD checks so the same class of bug doesn't recur.
- Track program health and report on trends, top vulnerability classes, and time‑to‑fix.
- Own the security posture of our CI/CD pipelines and deployment toolchain, including the custom DSL that translates to Kubernetes and Terraform.
- Integrate and tune SAST, DAST, and dependency/SCA scanning (e.g., Semgrep, CodeQL) as meaningful, low‑noise gates in Git Hub Actions.
- Implement secrets scanning, build/release integrity, artifact signing, and supply‑chain controls (SBOMs, provenance).
- Drive a security‑focused cleanup of existing pipelines and automate the manual, one‑off deployment steps that exist today.
- 8+ years focused on Application Security and/or offensive security (penetration testing, exploit development).
- Strong software‑development skills — you can read, write, and review production code rather than just operating tools. Experience with Kotlin and Gradle (and/or Swift/Android for mobile) is highly relevant to our stack;
Python for automation and custom tooling. - Deep mobile application security expertise across iOS and Android: OWASP MASVS/MASTG, cert pinning, secure storage, anti‑tampering/RE, and mobile testing tooling (Frida, objection, MobSF, Burp).
- Hands‑on penetration testing of web apps, mobile apps, and APIs, with the ability to demonstrate real exploitability.
- API security depth — OAuth/OIDC, REST and GraphQL, authn/authz and business‑logic…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).