Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Application Security Engineer

UNIUNI

Application Security Engineer

UniUni is a late-stage last-mile logistics company moving millions of parcels across the United States and Canada for some of the largest e-commerce platforms in North America. Our technology is cloud-native on AWS. We hold an active ISO 27001 certification and SOC 2 Type II attestation, and security is central to how we operate and how our customers trust us. This role reports to the Information Security Officer and is based in North America (remote with periodic travel to UniUni hubs).

About the Role

We are hiring an Application Security Engineer to be the senior technical anchor for product and platform security at UniUni. You will set the bar for how we build secure software, embed security into our engineering pipelines, and harden our customer-facing products. You will spend your time shoulder-to-shoulder with engineering, not adjacent to it.

This is a hands-on role. You will write code, review code, build tooling, and lead the technically hardest work across application security, DevSecOps and platform security, and product security. You will set standards that scale, but you will also dig into real systems to find real problems and ship real fixes.

What You'll Do
  • Application Security
  • Lead threat modeling on new and existing services, focusing on the systems where the risk is real and the architecture is in motion.
  • Run our secure code review program, including the design of review playbooks, the hardest reviews yourself, and coaching engineers to catch issues earlier.
  • Operate and tune our AppSec tooling stack across SAST, DAST, SCA, and secrets scanning, keeping signal high and noise low.
  • Own the third-party penetration testing program in partnership with the ISO, from scoping through findings triage and fix verification.
  • Drive standards for authentication, authorization, session management, and API security across our products, and engineer the hard parts yourself when needed.
Platform Security and DevSecOps
  • Embed security controls into our CI/CD pipelines so the secure path is the default path: pre-commit checks, build-time scans, signed artifacts, and policy-as-code gates.
  • Harden our cloud workloads on AWS, including container and Kubernetes security, secrets management, and runtime protections.
  • Codify infrastructure security baselines as IaC and policy (e.g., OPA/Conftest, AWS SCPs, Terraform guardrails) and own the rollout across the platform.
  • Partner with the platform team on identity-aware access to infrastructure, including non-human identities, short-lived credentials, and privileged access patterns.
Product Security
  • Engineer enterprise SSO (SAML 2.0 and OpenID Connect) into customer-facing products in support of contractual security commitments to enterprise shippers.
  • Set the technical direction for API security, including authentication, authorization, rate limiting, abuse prevention, and tenant isolation.
  • Drive secure-by-default patterns for data handling in our products, including encryption, key management, and access controls for customer and operational data.
  • Be the senior technical voice in customer security reviews when the questions go past what a questionnaire can answer.
Across All of It
  • Triage and lead response to application and platform security incidents, including root cause analysis and durable fixes.
  • Mentor engineers on secure design and secure coding, and raise the security fluency of the engineering organization through training, office hours, and example.
  • Contribute to ISO 27001 and SOC 2 evidence, control design, and audit readiness for the controls you operate.
Qualifications
  • 8+ years building and securing production software, with the last several focused on application security, product security, or DevSecOps as your primary discipline.
  • Deep, demonstrable software engineering ability. You read code fluently across multiple languages, you write production-quality code, and engineers respect your technical judgment.
  • Hands-on experience securing AWS workloads at scale, including IAM, networking, container and Kubernetes security, and IaC (Terraform or equivalent).
  • Working command of modern AppSec tooling (SAST, DAST, SCA, secrets scanning) and how to deploy it in a CI/CD pipeline without grinding delivery to a halt.
  • Strong threat modeling skills and a track record of turning models into shipped controls.
  • Practical experience implementing SAML 2.0 and OpenID Connect, and a clear mental model of identity, session, and authorization design
  • Experience leading the technical response to security incidents in production environments.
  • Ability to influence engineers and engineering leaders without authority. You explain risk in terms that engineers act on, and you partner rather than police.
Nice to Have
  • Experience in logistics, supply chain, marketplaces, or other high-volume transactional businesses.
  • Background contributing to or maintaining open source security tooling.
  • Prior experience supporting ISO 27001 or SOC 2 control design from the engineering side.
  • Offensive security background (CTFs, bug bounty, red team) that informs how you think about defense.
  • Experience hardening LLM-integrated or AI-powered features in production.
Why This Role

This is a senior IC role with real scope. You will set standards that the engineering organization actually adopts because you will have built them, shipped them, and proved they work. You will report to the Information Security Officer in a security function with executive commitment, a live ISO 27001 certification, and an active SOC 2 Type II attestation, and you will have the autonomy and the mandate to make UniUni's products and platform meaningfully more secure.

Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the Staff Application Security Engineer in United States vacancy
  • $67.67 - $112.78 per hour

     ...Job Description Title : Senior Application Security Engineer Location : Remote Job Type : Contract (12 Months) Compensation : $67.67 - $112.78/hr Industry: Retail --- About the Role We are partnering with a leading enterprise... 
    Suggested
    Contract work
    Remote work

    Dahl Consulting

    United States
    2 days ago
  • A leading IT staffing firm is seeking an experienced Application Security Engineer for a remote role lasting over 12 months. Candidates should have extensive experience in Static and Dynamic Application Security Testing, along with knowledge of Java, Python, and .NET. Familiarity... 
    Suggested
    Remote work

    Polarits

    Wilmington, DE
    3 days ago
  •  ...Perform expert-level secure code reviews focusing on OWASP Top 10 and CWE vulnerability...  .... Identify, triage, and remediate application-layer vulnerabilities, including broken...  ...strong relevant experience in software engineering or security operations with a focus on... 
    Suggested
    Remote work

    Crossing Hurdles

    New York, NY
    2 days ago
  • $130k - $218k

     ...A leading blockchain company is seeking a Senior Application Security Engineer to join their growing security team. The role involves embedding security throughout the software development lifecycle for MetaMask products, ensuring they meet high-security standards. Applicants... 
    Suggested
    Remote work

    ConsenSys

    New York, NY
    2 days ago
  • $175k

     ...Corporate Tools is hiring an Security Engineer for $175,000/year. You will be a traditional company employee. This is a full time 40 hour...  ...of security knowledge of testing mobile, native applications, web applications, distributed and database systems Must be... 
    Suggested
    Full time
    Work at office
    Remote work
    Flexible hours
    Weekend work

    Corporate Tools

    Austin, TX
    4 days ago
  •  ...Senior Application Security Engineer Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in web security, applied cryptography, software security vulnerabilities, IAM solutions, including federation... 
    Remote work

    InterSources

    United States
    7 hours ago
  • $140k - $170k

     ...and changing Stellar ecosystem. SDF is looking for a Senior Security Engineer to help shape and scale the security program across the Stellar...  ...forward to hearing from you! Privacy By submitting your application, you are agreeing to our use and processing of your data in... 
    Contract work
    Temporary work
    Work at office
    Local area
    Worldwide
    Flexible hours
    Night shift

    Energent Media

    New York, NY
    2 days ago
  • $150k - $160k

     ...Senior Cybersecurity Engineer (Application Security) The Senior Cybersecurity Engineer (Application Security) is responsible for protecting our...  ...details to partners and senior leadership, mentor junior staff, and provide technical direction to the program. Job Responsibilities... 
    For contractors
    Work at office
    Remote work
    Flexible hours

    United Natural Foods

    United States
    3 days ago
  •  ...and maintain $1.21 billion in surplus. Amerisure is hiring!! This role can sit remote . We're looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to... 
    Local area
    Remote work
    Flexible hours
    Shift work

    Amerisure Mutual Insurance Company

    United States
    5 days ago
  •  ...Swapcard Security Engineer Swapcard is the leading AI-powered event platform designed to drive revenue growth and foster meaningful connections...  ...tools (eg. Burp Suite). Solid understanding of common application vulnerabilities (OWASP Top 10, SSRF, IDOR, etc.).... 
    Work experience placement
    Remote work
    Work from home

    Swapcard

    United States
    3 days ago
  •  ...Senior Application Security Engineer We are seeking a highly skilled and proactive Senior Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This... 
    Remote work

    e.l.f Cosmetics

    United States
    3 days ago
  •  ...A dynamic tech startup is seeking a Sr. Application Security Engineer to oversee the security of their innovative product. This role requires a strong background in application security and Kubernetes, along with proficiency in Go. You will lead security reviews, threat... 
    Remote work
    Flexible hours

    vCluster

    Boston, MA
    4 days ago
  •  ...Appsecops Engineer The Application Security Engineer is responsible for designing, building, and maintaining the technical infrastructure that enables scalable application security across the organization. This role bridges software engineering and security disciplines... 
    Remote work

    Diverse Lynx

    United States
    5 days ago
  •  ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software... 
    Full time

    AGS INC

    San Francisco, CA
    3 days ago
  •  ...Must Have:- • Seeking candidates with solid expertise in Manual web application penetration testing and Manual secure code review. • Expertise is performing Manual Test Case Scenarios is a must. • Identification of Vulnerabilities in Source Codes manually is a must... 
    Remote work

    Yochana

    United States
    8 hours ago
  •  ...Application Security Engineer Client: Securian Financial Location: Remote - Preferrably local to St. Paul, MN (Will consider A+ candidates from permissible locations). The manager sees value in being able to come onsite, but he is open to considering fully remote... 
    Contract work
    Temporary work
    Local area
    Remote work

    Samprasoft

    United States
    2 days ago
  •  ...Application Security Engineer Location: Remote Purpose: The application security engineer shall have extensive experience in the involvement and understanding of cloud security controls (security-as-code) and target cloud infrastructure Google Cloud Platform (GCP... 
    Remote work

    Software Technology Inc

    United States
    5 days ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Brooklyn, NY
    4 days ago
  • $220k - $350k

     ...Senior Application Security Engineer [Remote-US] remote To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors... 
    Extra income
    Local area
    Remote work
    Work from home
    Home office

    Quanata

    New York, NY
    2 days ago
  •  ...Application Security Engineer AMERISAFE is seeking a detail-oriented, productivity driven professional to add to our Excellence Team. The Application...  ...and demonstrated ability to effectively communicate with staff, co-workers, management, and external personnel... 
    Work experience placement
    Remote work
    Weekend work

    AMERISAFE

    United States
    22 hours ago
  •  ...Application Security Engineer Location: Remote Duration: Fulltime Salary: 100K-120K/Year Roles and Responsibilities Must have technical/functional skills. Candidate must be a leader with hands-on engineer with cross-vertical technical expertise encompassing... 
    Full time
    Remote work

    Diverse Lynx

    United States
    8 hours ago
  • $180k - $225k

     ...open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things...  ...Join our dynamic team as a Senior Application Security Engineer , where you'll play a pivotal role in securing the Temporal... 
    Full time
    Temporary work
    Part time
    Remote work
    Work from home
    Home office

    Temporal Technologies

    United States
    2 days ago
  •  ...Application Security Engineer This role is primarily focused on security administration for ERP applications such as Oracle HCM Cloud, PeopleSoft HCM and Peoplesoft Financials. Under general direction, defines, implements, and maintains application security processes... 
    Remote work

    TriOptus LLC

    United States
    2 days ago
  •  ...A venture-backed tech startup is seeking a Sr. Application Security Engineer to oversee the security of their innovative product. This role focuses on ensuring secure multi-tenancy within Kubernetes, leading threat modeling initiatives, and managing vulnerability lifecycles... 
    Remote work
    Flexible hours

    vCluster

    Saint Louis, MO
    23 hours ago
  •  ...A healthcare client is looking for 2 JR level Application Security Engineers to sit fully remote. The 2 Engineers are going to be joining the DevSecOps team working alongside 9-12 developers/engineers. They will be part of an initiative of migrating all application security... 
    Remote work

    Insight Global

    United States
    4 days ago
  • $62k - $141k

     ...Job Number: R0231845 Location: Washington,DC,US Share job via: Share Application Security Engineer The Opportunity: Work together with the client and application community to maintain a resilient security posture... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    United States
    1 day ago
  • Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation...  ...innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle. Job... 

    Bloomberg Industry Group

    Arlington, VA
    11 hours ago
  •  ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution... 
    Remote work
    All shifts
    Shift work

    RegScale

    United States
    10 hours ago
  •  ...VECTOR JOB OPENING JOB TITLE: Application Security Engineer JOB ID: 575 JOB CLEARANCE REQUIRED: TS/SCI clearance must be active. PRACTICE AREA: System Engineering LOCATION; Bethesda, Maryland (Hybrid) Onsite and remote work. PAY: W2 Salaried 1250... 
    Contract work
    Remote work
    Monday to Friday
    Flexible hours

    Vector Talent Resources

    United States
    3 days ago
  •  ...A tech startup is looking for a Sr. Application Security Engineer to secure their Kubernetes multi-tenancy solutions. This role involves core product security, threat modeling, and vulnerability management while collaborating on feature development. Ideal candidates will... 
    Remote work
    Flexible hours

    vCluster

    Salt Lake City, UT
    23 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Application Security Engineer. Be the first to apply!