Senior Application Security Engineer
About the role We're looking for a Senior Application Security Engineer. You own security in the software development lifecycle (SDLC) — end to end, hands-on, and independently. You report to the CISO. The CISO sets direction, risk appetite, and handles executive escalation; you run application security day to day without needing constant support. You'll partner with engineering teams to find, fix, and prevent vulnerabilities in a platform built primarily on .NET and hosted in Azure, while helping us secure the next generation of AI-powered features. This is a hands-on role for someone who wants to make secure development the path of least resistance for our engineers.
What you’ll do · Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs. Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs. · Security tooling in CI/CD.
Build, integrate, and operate SAST, SCA, and DAST in Azure DevOps pipelines, including PR gating on new critical and high findings, secret scanning, and automated routing of findings to tickets. · Azure security. Secure our cloud estate across identity and access management (Entra ID, Auth0), network configuration, secrets management, and workload protection, working with Defender for Cloud policy and posture. · Threat modeling and reviews.
Conduct threat models, design reviews, and code reviews for new and existing services — with a threat model in place before any new service reaches production. · AI feature security. Evaluate security and privacy implications of our AI functionality, including LLM-specific risks such as prompt injection, data leakage, and model misuse, and define controls for them. · Standards and enablement.
Define and uphold secure coding standards, train engineers, and build a security champion in each product team so risk assessment becomes self-service rather than a security-team bottleneck. · Pen tests and scans. Coordinate penetration tests and application vulnerability scanning, review the findings, identify fixes, and implement them hands-on when needed. · Incident response. Support security incident investigation and response as the application subject-matter expert, working with our 24/7 managed detection and response partner.
What you’ll bring · 8+ years of experience in application security, or in software engineering with a strong security focus. · Experience integrating and operating security tooling within CI/CD pipelines. NET (C#) working knowledge; ability to read and reason about Python is a plus. · Fluency in common vulnerability classes (OWASP Top 10, API security risks) and how they manifest in real code — not just in scanner output. · Hands-on Azure experience: creating resources, securing applications, Azure networking, and secrets management.
· Hands-on experience with Auth0 in production environments. · Strong communication skills and the ability to influence engineers without owning their backlog. · A pragmatic, risk-based mindset that balances security with delivery — you know which findings matter and which are noise