Security engineer, application security
San Francisco, San Francisco County, California, 94199, USA
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
WRITER is seeking an Application Security Engineer with deep expertise in App Sec, Dev Sec Ops automation, and red team operations to secure their AI and AGI applications. The role involves integrating security into development pipelines, conducting penetration testing, and collaborating with cross‑functional teams to safeguard AI solutions.
H1B Sponsor Likely
Responsibilities- Embed security in the build pipeline — Own pre‑deployment application security, including automated vulnerability scanning, container scanning, and custom security gates in CI/CD
- Conduct advanced application penetration testing — Perform comprehensive testing on AI applications, APIs, and model endpoints, simulating adversarial attacks to validate controls
- Automate security testing at scale — Develop scripts, tools, and frameworks for continuous security assessment, including SAST, DAST, and SCA integration
- Lead application‑layer red team exercises — Plan and execute engagements that mimic sophisticated adversary techniques targeting AI systems
- Hunt and validate vulnerabilities — Discover, reproduce, and chain vulnerabilities into realistic attack paths, providing actionable remediation guidance
- Advise on security architecture — Review designs for weaknesses, create secure patterns, and identify systemic issues across applications
- Collaborate across boundaries — Partner with Cloud/Infrastructure on deployment/runtime security, AI Security on threat modeling, and Detection & Response on defensive validation
- Application security Penetration testing Dev Sec Ops automation CI/CD integration Vulnerability discovery SAST tools DAST tools API security Exploit development Security architecture Purple team operations Collaboration
- 8+ years in application security, with a strong focus on hands‑on testing
- 5+ years conducting penetration tests and security assessments
- Proven record of finding and exploiting critical vulnerabilities
- Deep experience integrating security into Dev Ops workflows and CI/CD pipelines
- Strong programming skills for exploit development and security automation
- Expertise in web application and API security, including cloud‑native architectures
- Proficient with penetration testing tools (e.g., Burp Suite, OWASP ZAP, custom scripts)
- Skilled in SAST, DAST, and SCA tools
- Strong understanding of application‑layer attack techniques and exploitation
- Experience with supply chain security and build pipeline hardening
- Demonstrated ability to identify vulnerabilities others miss Proven track record of automating security testing in fast‑paced development cycles
- Ability to translate red team findings into concrete defensive measures
- History of effective collaboration with engineering teams
- Background in software development or Dev Ops
- Experience testing AI/ML applications
- Security certifications such as OSCP, OSWE, or GWAPT
- Published security research or CVEs
- Experience with purple team operations
- Medical, dental, and vision coverage for you and your family
- Paid parental leave for all parents (12 weeks)
- Fertility and family planning support
- Early‑detection cancer testing through Galleri
- Flexible spending account and dependent FSA options
- Health savings account for eligible plans with company contribution
- Annual work‑life stipends for: + Home office setup, cell phone, internet + Wellness stipend for gym, massage/chiropractor, personal training, etc. + Learning and development stipend
- Company‑wide off‑sites and team off‑sites
- Competitive compensation, company stock options and 401k
Relocations, information management, payment services, and realty services.
Writer Corporation has a track record of offering H1B sponsor ships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. ( Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
92 %
Represents job field similar to this job
Application security Penetration testing Dev Sec Ops automation CI/CD integration Vulnerability discovery
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).