Senior Application Security Engineer

1 month, 4 weeks ago
Full-time
Senior
Cybersecurity
Apollo.io

Apollo.io

Apollo.io is a sales intelligence platform that helps businesses find, engage, and convert leads at scale with a database of over 275 million contacts and 73 million companies.

Professional Services
251-1K
Founded 2015
$251M raised

Description

  • Own and continuously improve the secure software development lifecycle for Apollo applications.
  • Perform application security reviews, threat modeling, and deep code-level analysis for high-impact features before launch.
  • Provide practical security architecture guidance to Engineering, Product, and IT teams.
  • Define and maintain application-security guardrails, secure design expectations, code review standards, and risk models.
  • Drive vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other security signals.
  • Validate findings, prioritize risk, route issues, and track remediation and verification through SLAs.
  • Read code, identify root cause, propose fixes, and directly implement or support remediation for complex vulnerabilities.
  • Perform hands-on validation and offensive testing, including exploit development, bypass testing, and red-team-style exercises.
  • Configure and improve AppSec tooling, integrations, dashboards, and related controls to reduce noise and improve coverage.
  • Embed AI-specific security checks into SSDLC reviews and partner on secure design for AI systems and AI-powered features.
  • Support security enablement for engineers and security champions through training, guidance, secure patterns, and documentation.
  • Produce clear metrics, narratives, and written documentation to improve AppSec visibility and decision-making.

Requirements

  • 5+ years of software engineering or application security experience in modern SaaS environments.
  • Strong software development skills with the ability to read, write, and ship production code.
  • Ruby experience is highly valuable; Python or similar scripting ability is a plus.
  • Strong Linux and cloud fundamentals, ideally with experience in GCP-backed environments.
  • Deep familiarity with common AppSec issues, secure design, authentication and authorization, vulnerability management, and developer security tooling.
  • Demonstrated ability to perform deep code review, penetration testing, and exploit-oriented validation.
  • Ability to fix vulnerabilities directly or work closely with engineers to land durable remediations.
  • Experience handling findings from bug bounty programs, pentests, internal reviews, or automated security tooling through closure and verification.
  • Experience using AI-assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale.
  • Experience securing AI-powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring expectations.
  • Strong written and verbal communication, stakeholder management, and influencing skills.
  • Preferred: experience supporting or leading security reviews for AI-native products, internal agents, or AI-assisted engineering workflows.
  • Preferred: experience improving secure-by-design practices and AppSec observability in a fast-moving engineering organization.
  • Preferred: experience with security training, developer enablement, or security champions programs.
  • Preferred: relevant security certifications.

Benefits

  • Tier 1 pay range: $218,000–$273,000 USD for San Francisco, New York City, and Seattle.
  • Tier 2 pay range: $190,000–$237,000 USD for all other US locations.
  • Additional equity may be included.
  • Company bonus or sales commissions/bonuses may be included.
  • 401(k) plan.
  • At least 10 paid holidays per year plus flex PTO.
  • Parental leave.
  • Employee assistance program and wellbeing benefits.
  • Global travel coverage.
  • Life, AD&D, STD, and LTD insurance.
  • FSA/HSA and medical, dental, and vision benefits.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
16 hours, 8 minutes ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
16 hours, 53 minutes ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 days, 15 hours ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 days, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers