À propos de ce poste Staff Application Security Engineer (R5949) chez Shieldai
The successful candidate combines technical application-security depth with the programmatic leadership to drive enterprise-wide improvement. You will help teams build, test, package, release, and maintain secure software while ensuring security controls are practical, measurable, and integrated into existing engineering workflows.
This is a Staff level individual-contributor role with significant influence across engineering, security, product, and technology leadership.
What you'll do:
* Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.
* Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.
* Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.
* Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.
* Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.
* Evaluate, implement, tune, and operationalize application-security tooling, including:* Static application security testing (SAST)
* Dynamic application security testing (DAST)
* Software composition analysis (SCA)
* Secrets detection
* Infrastructure-as-code security scanning
* Container and image security scanning
* API and cloud-native application security controls
* Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.
* Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.
* Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.
* Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.
* Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.
* Mature software supply-chain security practices, including:* Machine-readable software bills of materials (SBOMs)
* Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications
* Build and release provenance
* Artifact, package, container-image, and binary signing
* Artifact verification and trusted promotion processes
* Secure artifact repositories and package registries
* Approved dependency sources and package integrity verification
* SLSA-aligned build integrity, provenance, and release controls
* Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.
* Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
* Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.
* Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.
* Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
* Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.
NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.
Required qualifications:
* Demonstrated experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams.
* Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.
* Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices.
* Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling.
* Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
* Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition.
* Knowledge of common application-security risks, including authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.
* Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
* Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.
* Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable secure-development and supply-chain security frameworks.
* Ability to read and assess production code and scripts in one or more modern programming languages.
* Strong written and verbal communication skills, including the ability to explain technical risk and tradeoffs to developers, leaders, auditors, and nontechnical stakeholders.
Preferred qualifications:
* Experience with VEX, CSAF, SBOM formats such as SPDX or CycloneDX, and component or vulnerability intelligence workflows.
* Experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.
* Experience with common source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.
* Experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies.
* Experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements.
* Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance product environments.
* Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.