Senior Application Security Engineer [Remote-US]

1 month, 2 weeks ago
Full-time
Senior
Software Development
Quanata

Quanata

Quanata is a software development company based in San Francisco, specializing in context-based insurance solutions. The company leverages AI, real-time telematics, and data science to enhance risk prediction, promote safer driving behaviors, and create modern insurance products. Quanata aims to transform the insurance industry by fostering positive behaviors and advancing digital experiences. The company develops a range of software platforms and tools for insurers. Their offerings include AI-powered risk assessment, telematics for driver monitoring, and claims solutions that optimize and automate processes. Quanata also focuses on customer engagement through personalized products and retention tools, supporting insurtech modernization with big data analytics and cloud-native platforms. With a team of around 26 professionals, Quanata draws on talent from Silicon Valley to drive innovation in the insurance sector.

information technology & services
201-500

Description

  • Partner with a product portfolio to manage product security, with emphasis on AI/ML-specific security concerns.
  • Perform security design reviews and threat modeling for APIs, web features, and service integrations.
  • Integrate and support SAST, SCA, and DAST tools within CI/CD pipelines and developer workflows.
  • Review source code and deployment configurations for security vulnerabilities.
  • Collaborate with developers to triage, fix, and validate vulnerability findings.
  • Participate in cross-functional incident response and remediation planning.
  • Draft and maintain application security guidance for engineering teams and security champions.
  • Contribute to security awareness and enablement across the engineering organization.
  • Develop application security integrations and automation deployments, including ASVS scanning and Burp Suite Enterprise.
  • Support application security integration reviews, SaaS security assessments, and open source software reviews.

Requirements

  • Bachelor’s degree or equivalent relevant experience.
  • 6-8 years of experience in application security or full-stack development with security expertise.
  • Strong understanding of secure coding in JavaScript/TypeScript, Node.js, and web standards.
  • Familiarity with application risk and vulnerabilities such as OWASP Top 10, API security issues, and SSRF.
  • Experience with code scanning tools such as CodeQL, Semgrep, SonarQube, or Snyk.
  • Ability to read and debug complex codebases across the stack.
  • Clear and thoughtful communication skills, with the ability to guide engineers at all levels.
  • Working knowledge of offensive security testing such as pentesting or bug bounties.
  • Experience with GraphQL security is preferred.
  • Participation in security champions programs or secure SDLC rollouts is preferred.
  • Contributions to open-source security tooling are preferred.
  • Familiarity with infrastructure-as-code and container security is preferred.

Benefits

  • Salary range of $220,000 to $350,000.
  • Medical, dental, vision, life insurance, and supplemental income plans for employees and dependents.
  • Headspace app subscription and a monthly wellness allowance.
  • 401(k) plan with company match.
  • One-time $2,000 home office equipment stipend for remote work.
  • Four weeks of PTO in the first year.
  • Twelve weeks of fully paid parental leave for new parents.
  • Up to $5,000 per year for professional learning, continuing education, and career development, plus LinkedIn Learning and BetterUp coaching access.
  • Remote-first work environment in the U.S. with core meeting hours from 9AM to 2PM Pacific time.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Arquiteto de Segurança em Desenvolvimento (AppSec) Senior

Harford County Public Library 51-250 Diversified Consumer Services

Stone Tech, parte da Stone Co., is hiring a Senior Application Security Architect to help secure the development and operation of payment and financial systems, including products that use LLMs and generative AI.

Agile AWS Azure CI/CD GCP Generative AI LLM
12 hours, 34 minutes ago

Application Engineer

Parachute Health 51-250 Health Care Providers & Services

Parachute Health is hiring a software engineer for its IT & Security team to build internal platforms and AI-driven workflows that improve security, compliance, and operational efficiency across its healthcare technology environment.

AWS Datadog EC2 GCP GitHub GraphQL HIPAA JavaScript Node.js Penetration Testing Python React REST API Ruby on Rails SIEM Splunk SQL TDD TypeScript
13 hours, 19 minutes ago

Application Security Engineer

Swapcard 251-1K Professional Services

Swapcard is hiring an Application Security Engineer to strengthen the security of its AI-powered event platform by driving vulnerability remediation, security testing, and secure development practices across the product lifecycle.

Burp Suite CI/CD GitLab CI Helm Jenkins Penetration Testing SonarQube Terraform WAF
1 day, 13 hours ago

Senior Security Engineer II, Application Security (Remote Eligible)

Smartsheet 1K-5K Internet Software & Services

Smartsheet is hiring a Senior Security Engineer II to strengthen application security for its global SaaS platform by securing AI-integrated features, expanding security automation, and leading high-impact security reviews.

AWS Azure CI/CD GCP GitLab Go Java JavaScript LLM Penetration Testing Python Ruby TypeScript
4 days, 13 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers