Application Security Engineer
Listed on 2026-08-30
-
IT/Tech
Cybersecurity
Zof AI is seeking an Application Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and the enterprise controls that buyers audit before they trust us with a repository. If you have worked as an Application Security Engineer, Product Security Engineer, Cloud Security Engineer, or Infrastructure Security Engineer, this is that discipline at Zof AI.
The ideal candidate thinks in threat models, ships controls instead of policy documents, and treats customer code as the most sensitive asset we hold.
Engineering
· Mid to Senior
· Full-time
· On-site
· San Francisco, CA
- Own the security posture of a platform that reads, executes, and modifies customer source code.
- Harden the sandbox, tenant, and workload isolation boundaries agents run inside.
- Design secrets management, credential handling, and least privilege access across the platform.
- Secure the software supply chain from dependencies through build and deploy.
- Build the technical controls behind SOC 2 and enterprise security requirements.
- Teach our agent fleets to find, prove, and remediate real vulnerabilities in customer code.
- Run threat modeling, design reviews, and incident response as a regular practice.
- Partner with engineering and sales to clear enterprise security reviews and questionnaires.
- Experience securing production software systems or cloud infrastructure.
- Strong software engineering foundation and comfort shipping code, not just reviewing it.
- Working knowledge of application security and common vulnerability classes.
- Experience with cloud security, identity, and access control.
- Familiarity with compliance frameworks such as SOC 2.
- Clear written and verbal communication.
- Comfort operating in a fast-moving environment.
- High ownership of security outcomes, not just findings.
- Experience with sandboxing, container isolation, or multi-tenant architecture.
- Experience with LLM or agent security, including prompt injection and tool use risk.
- Experience with static analysis, fuzzing, or automated vulnerability detection.
- Experience leading enterprise security reviews or SOC 2 audit readiness.
Hands-on experience working with AI agents and threat modeling what they are allowed to do is required
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).