Staff Application Security Engineer (R5949)

3 hours, 15 minutes ago
Full-time
Lead
Cybersecurity
Bitly

Bitly

Bitly is a link management platform offering URL shortening, QR codes, and a Link in Bio solution for brands to optimize customer experience.

Internet Software & Services
51-250
Founded 2008
$92M raised

Description

  • Establish and continuously improve company-wide secure SDLC policies, standards, controls, procedures, and evidence requirements.
  • Assess engineering, CI/CD, source-control, build, and release maturity and lead improvement roadmaps.
  • Develop secure-development guidance, reference architectures, reusable patterns, guardrails, exception processes, and enablement materials.
  • Partner with development teams to triage, prioritize, remediate, and verify application-security findings.
  • Implement and operationalize SAST, DAST, SCA, secrets detection, infrastructure-as-code, container, API, and cloud-native security controls.
  • Lead threat modeling, security requirements definition, and secure design reviews for high-risk applications and changes.
  • Establish risk-based vulnerability, third-party dependency, open-source governance, and software supply-chain security processes.
  • Secure CI/CD pipelines through least-privilege access, protected branches, secret handling, hardened build environments, and release approvals.
  • Create and lead a security champions program with training, office hours, secure-coding guidance, and developer tools.
  • Develop executive metrics and reporting covering AppSec risk, remediation, control coverage, supply-chain integrity, and program maturity.

Requirements

  • 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a related field.
  • Experience designing, implementing, or maturing secure SDLC or application-security programs across multiple engineering teams.
  • Strong knowledge of secure coding, application-security testing, vulnerability management, software delivery, and DevSecOps.
  • Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related tools.
  • Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
  • Experience facilitating threat modeling, security design or architecture reviews, and security requirements definition.
  • Knowledge of common application-security risks, including authentication, authorization, API security, injection, insecure dependencies, secrets exposure, and business-logic vulnerabilities.
  • Experience with SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
  • Familiarity with NIST SP 800-218/SSDF, OWASP SAMM, SLSA, or comparable frameworks; preferred experience includes NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, or SOC 2.
  • Ability to assess production code in a modern programming language and communicate technical risks to technical and nontechnical stakeholders; relevant certifications and experience with cloud-native, Kubernetes, API, IaC, or AppSec tools are preferred.

Benefits

  • Full-time package includes salary within the listed range, bonus, benefits, and equity.
  • Temporary employees receive pay within the listed range and a temporary benefits package after 60 days.
  • Offers may be influenced by experience, skills, certifications, licenses, and work location.
  • Equal opportunity workplace with reasonable accommodations available for disabilities or special needs.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Mobile Software Engineer (iOS / Android), Identity & Security - India

JumpCloud 251-1K Internet Software & Services

JumpCloud is hiring a Senior Mobile Software Engineer to build secure native iOS and Android applications that protect enterprise identities through authentication, password management, and identity verification.

Android AWS CI/CD Encryption Espresso GCP GitHub Actions Go iOS Kotlin OpenID Connect REST API Swift WebSockets XCTest
2 hours, 45 minutes ago

Application Security Engineer

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for large-scale bug bounty programs while coordinating with clients and security researchers.

Burp Suite Nmap
1 day, 2 hours ago

Senior Product Security Engineer

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Senior Product Security Engineer to secure its AI-native market intelligence platform by embedding AI/ML security, secure architecture, and assurance practices across the product lifecycle.

CI/CD DevSecOps Encryption Java JavaScript Kubernetes Python SAML Secrets Management TLS
1 day, 2 hours ago

Product Security Engineer

Modern Health 251-1K Health Care Providers & Services

Modern Health is hiring a remote Product Security Engineer to strengthen security and compliance across its mental health platform, applications, cloud infrastructure, and software development lifecycle.

Agile AWS Bash CI/CD Cybersecurity Datadog Django Flask GitLab HashiCorp Vault Packer Penetration Testing PostgreSQL Python Redis Terraform
3 days, 3 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers