×
Register Here to Apply for Jobs or Post Jobs. X

Lead Application Security Engineer

Job in San Francisco, San Francisco County, California, 94199, USA
Listing for: Qplusequality
Full Time position
Listed on 2026-03-01
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 142000 - 184500 USD Yearly USD 142000.00 184500.00 YEAR
Job Description & How to Apply Below
Position: Lead Application Security Engineer - 11006

Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter, more profitable business decisions to improve operating margins.

Why

join Coupa?

🔹 Pioneering Technology:
At Coupa, we're at the forefront of innovation, leveraging the latest technology to empower our customers with greater efficiency and visibility in their spend.

🔹 Collaborative Culture:
We value collaboration and teamwork, and our culture is driven by transparency, openness, and a shared commitment to excellence.

🔹 Global Impact:
Join a company where your work has a global, measurable impact on our clients, the business, and each other.

Learn more on Life at Coupa blog and hear from our employees about their experiences working at Coupa.

The Impact of a Lead Application Security Engineer at Coupa:

We are looking for an extremely talented Lead Application Security Engineer to join our Application Security Team. You will be part of a global agile group that is responsible for building the best-in‑class SaaS platform, deployment infrastructure, and services. The position will require a candidate to drive security architecture, perform design and threat modeling reviews
, and design, develop, maintain, and scale Coupa’s security features and application security tooling. This role is critical in ensuring the security of our cutting‑edge, highly scalable platform, including the review and guidance for new technological domains such as Artificial Intelligence (AI) and Machine Learning (ML) systems
.

What You’ll Do:
  • Expand the application security landscape at Coupa
  • Being a hands‑on developer is a key responsibility in this role, with strong proficiency in secure coding practices
  • Strong software development skills in languages such as Java, .Net, and Python
  • Ability to perform code reviews and mentor junior team members
  • Passion for building security‑focused features that perform at scale
  • Track vulnerability reports and contribute security fixes
  • Design and implement application changes to meet security compliance requirements
  • Lead and execute Security Architecture Reviews, Threat Modeling, and Design Reviews for new and existing platform components to proactively identify and mitigate security risks.
  • Conduct Security Reviews for AI/ML models and systems
    , addressing unique risks associated with data integrity, model poisoning, privacy, and adversarial attacks.
  • Evaluate new security technologies and make recommendations to strengthen our application
  • Be a champion of Coupa’s Secure Software Development Lifecycle (
    SSDLC
    ) methodologies, integrating security earlier into the development pipeline.
  • Work closely with the Operations Security team to review and define our best practices
What You Will Bring to Coupa:
  • Leadership &

    Experience:

    2+ years as a Lead Software Engineer or Lead App Sec Engineer; able to independently drive projects from design through delivery.
  • Technical Expertise: Strong in Java, .NET, or Python; experienced building secure web applications/microservices and designing complex, distributed systems.
  • Security Architecture & Threat Modeling: Skilled in formal security architecture/design reviews and threat modeling methods (STRIDE, DREAD).
  • Security Foundations: Deep knowledge of OWASP Top 10, SANS Top 25, identity and access management (SAML, OIDC, SSO), OAuth flows, and core cryptographic algorithms (DES, RSA, HMAC, SHA, etc.).
  • Systems & Development Practices: Familiar with design patterns, scalability, high availability, concurrency, and SQL/No

    SQL databases; strong communication, self‑motivation, and continuous learning mindset.
  • Additional/Preferred

    Skills:

    Background in AI/ML security (MLOps, adversarial robustness), compliance frameworks (HIPAA, PCI, SOX, FedRAMP), plus conference presentations or open‑source contributions.

The estimated pay range for this role is $142,000 - $184,500

The starting salary for the successful candidate will be based on…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary