Senior Application Security Engineer [Remote-US]

3 weeks, 4 days ago
Full-time
Senior
Software Development
Quanata

Quanata

Quanata is a software development company based in San Francisco, specializing in context-based insurance solutions. The company leverages AI, real-time telematics, and data science to enhance risk prediction, promote safer driving behaviors, and create modern insurance products. Quanata aims to transform the insurance industry by fostering positive behaviors and advancing digital experiences. The company develops a range of software platforms and tools for insurers. Their offerings include AI-powered risk assessment, telematics for driver monitoring, and claims solutions that optimize and automate processes. Quanata also focuses on customer engagement through personalized products and retention tools, supporting insurtech modernization with big data analytics and cloud-native platforms. With a team of around 26 professionals, Quanata draws on talent from Silicon Valley to drive innovation in the insurance sector.

information technology & services
201-500

Description

  • Partner with a product portfolio to manage product security, with emphasis on AI/ML-specific security concerns.
  • Perform security design reviews and threat modeling for APIs, web features, and service integrations.
  • Integrate and support SAST, SCA, and DAST tools within CI/CD pipelines and developer workflows.
  • Review source code and deployment configurations for security vulnerabilities.
  • Collaborate with developers to triage, fix, and validate vulnerability findings.
  • Participate in cross-functional incident response and remediation planning.
  • Draft and maintain application security guidance for engineering teams and security champions.
  • Contribute to security awareness and enablement across the engineering organization.
  • Develop application security integrations and automation deployments, including ASVS scanning and Burp Suite Enterprise.
  • Support application security integration reviews, SaaS security assessments, and open source software reviews.

Requirements

  • Bachelor’s degree or equivalent relevant experience.
  • 6-8 years of experience in application security or full-stack development with security expertise.
  • Strong understanding of secure coding in JavaScript/TypeScript, Node.js, and web standards.
  • Familiarity with application risk and vulnerabilities such as OWASP Top 10, API security issues, and SSRF.
  • Experience with code scanning tools such as CodeQL, Semgrep, SonarQube, or Snyk.
  • Ability to read and debug complex codebases across the stack.
  • Clear and thoughtful communication skills, with the ability to guide engineers at all levels.
  • Working knowledge of offensive security testing such as pentesting or bug bounties.
  • Experience with GraphQL security is preferred.
  • Participation in security champions programs or secure SDLC rollouts is preferred.
  • Contributions to open-source security tooling are preferred.
  • Familiarity with infrastructure-as-code and container security is preferred.

Benefits

  • Salary range of $220,000 to $350,000.
  • Medical, dental, vision, life insurance, and supplemental income plans for employees and dependents.
  • Headspace app subscription and a monthly wellness allowance.
  • 401(k) plan with company match.
  • One-time $2,000 home office equipment stipend for remote work.
  • Four weeks of PTO in the first year.
  • Twelve weeks of fully paid parental leave for new parents.
  • Up to $5,000 per year for professional learning, continuing education, and career development, plus LinkedIn Learning and BetterUp coaching access.
  • Remote-first work environment in the U.S. with core meeting hours from 9AM to 2PM Pacific time.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Intern

Funding Societies 251-1K Capital Markets

Funding Societies | Modalku is seeking a Product Security Intern to help strengthen secure software development and security automation across its engineering environment using Generative AI and modern security tooling.

Bash CI/CD Cybersecurity Encryption Generative AI Git Go JavaScript LLM Penetration Testing Python
1 hour, 1 minute ago

Staff Product Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Staff Product Security Engineer to embed security into cloud-native product delivery, harden Kubernetes and CI/CD environments, and reduce supply chain risk across its open source build platform.

AWS CI/CD GCP GitHub Actions Go Kubernetes OWASP Penetration Testing Python Secrets Management Tekton
2 hours, 9 minutes ago

Senior Application Security Engineer

Onit 251-1K IT Services

Onit is hiring a Senior Application Security Engineer in Pune to secure its SaaS applications, APIs, and AI-driven platform through hands-on security architecture, risk assessment, and vulnerability management.

AWS Azure CI/CD DevSecOps GCP GraphQL OAuth OpenID Connect REST API SAML SonarQube System Design
9 hours, 53 minutes ago

Application Security Engineer

Brex 1K-5K Diversified Financial Services

Brex is hiring an Application Security Engineer to help secure its finance platform by finding and responding to vulnerabilities, supporting secure development, and contributing to AI security efforts across cross-functional teams.

AWS GraphQL gRPC Kotlin Kubernetes Penetration Testing Python
11 hours, 45 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers