Staff Application Security Engineer
$114k - $240kReltio Inc.
Role Description
As a senior individual contributor on the Application Security team, the Staff Application Security Engineer will help to define and drive Reltio’s application and product security architecture across a distributed, cloud-native SaaS platform. This role helps in the technical direction for securing how Reltio designs, builds, and ships software—helps to define the strategy and roadmap for secure SDLC, shift-left automation, and the secure adoption of API-driven and AI/agentic technologies.
The Staff Application Security Engineer will partner with the Engineering, DevOps, Product, and Release Management teams to embed security as a foundational part of software design and delivery. The successful candidate will set standards, mentor and uplevel other security and engineering staff, lead complex threat modeling and architecture reviews, and develop novel techniques to identify and stop application- and AI-layer attacks—protecting Reltio’s intellectual property and customer data globally.
Job Duties and Responsibilities
- Security Architecture & Technical Leadership
- Serve as the senior application security subject matter expert, providing guidance on industry best practices, secure design patterns, and defense-in-depth strategies for the product security architecture.
- Helps to define and drive the overall application/product security architecture, vision, strategy, and roadmap across Reltio’s platform and services.
- Influence engineering architecture and roadmap decisions without direct authority, driving risk-based consensus across teams.
- Mentor and uplevel application security engineers and development teams, raising the secure-coding maturity of the broader organization.
- Secure Development Lifecycle & Shift-Left
- Embed security throughout the SDLC, from design through deployment, and define secure coding standards and best practices adopted across teams.
- Drive shift-left initiatives by providing guidance, tooling, paved-road patterns, and remediation support that enable engineers to build securely from the outset.
- CI/CD Pipeline Security
- Design and implement security controls within CI/CD pipelines, enabling automated security testing and vulnerability detection at scale.
- Operationalize SAST, SCA, DAST, and secrets scanning as policy-driven, low-friction gates; partner with release management on secure deployment checks and policy compliance.
- Threat Modeling & Risk Assessment
- Lead threat modeling sessions for complex, high-impact systems to identify and mitigate security risks early in design and architecture phases.
- Perform technical risk assessments of new technology and ensure solutions meet secure architecture designs; assess, measure, and clearly communicate risk impact to stakeholders.
- Vulnerability Management
- Analyze and validate remediation of application security findings from SAST, SCA, DAST, API testing, penetration tests, and manual assessments.
- Drive risk-based prioritization of fixes, reduce false positives, and provide clear, actionable remediation guidance with proper pre-release validation.
- API Security
- Partner with engineering to ensure secure API design and implementation; identify and mitigate authentication/authorization issues, data exposure, rate-limiting gaps, and OWASP API Top 10 risks.
- AI & Agentic Security (Guardrails, MCP, LLM)
- Helps to define AI security guardrails for Reltio’s AI and multi-agent platforms, addressing prompt/output validation, insecure model usage, data leakage, and tenant-isolation concerns.
- Establish security standards for Model Context Protocol (MCP) servers and tools—covering tool authorization, scoping, and abuse prevention—and lead threat modeling of agentic workflows (autonomous tool use, indirect prompt injection, excessive agency).
- Develop new and novel defense techniques to detect and stop advanced application- and AI-layer adversary tactics, and evaluate AI-assisted security tooling to scale detection and remediation.
- Penetration Testing & Security Validation
- Perform and oversee application, API, and AI/agent penetration testing; build and curate test payloads (including prompt-injection and guardrail bypass suites) and validate control effectiveness.
- Training, Collaboration & Continuous Improvement
- Deliver secure-coding, API, and AI-security guidance and hands-on support during code and design reviews.
- Partner with DevOps, QA, Engineering, Product, and Release Management to integrate security requirements throughout development and release.
- Stay current on emerging application, API, and AI/agentic security threats and continuously improve security processes, tooling, and overall posture.
- Investigate security events and incidents leveraging security tooling, and support customer-facing security communications as needed.
Qualifications
- 8+ years of experience in application security or software development, including significant time in a cloud-native or SaaS environment.
- Demonstrated technical leadership as a senior individual contributor: setting standards, driving cross-team initiatives, and influencing architecture without direct authority.
- Hands-on experience with secure coding practices and modern application development; proficiency leading secure code reviews.
- Strong understanding of cloud well-architected frameworks, application development, and deployment workflows.
- Strong understanding of application security vulnerabilities (OWASP Top 10) and prevention strategies.
- Strong understanding of API security principles and the OWASP API Top 10.
- Experience integrating security into CI/CD and release management processes (e.g., Jenkins, ArgoCD, or similar).
- Experience with application security testing methodologies—SAST, SCA, and DAST—integrated into CI/CD pipelines.
- Experience with AI security concepts, including guardrails, prompt and output validation, data protection, and MCP security.
- Hands-on experience with web technologies such as Java, Java Spring Boot, JavaScript, Node.js, C#, modern UI frameworks, microservices, and cloud-native/serverless architectures.
- Experience with AWS, GCP, and/or Azure, and securing containerized environments and Kubernetes.
- Hands-on experience with Burp Suite Pro for web and API testing.
- Experience with modern application security platforms, with Wiz preferred (other AppSec tools acceptable).
- Strong communication and presentation skills, with the ability to educate, collaborate, and drive risk-based consensus.
- Self-starter with a history of driving technical initiatives; adaptable, agile, and effective in global, distributed teams.
Skills That Are Nice to Have
- Hands-on experience securing LLM applications and multi-agent systems, including agentic guardrail frameworks (e.g., NeMo Guardrails, AWS Bedrock Guardrails) and MCP gateway/tool security.
- Experience building or operationalizing AppSec automation/orchestration (SAST/SCA/secrets + AI analysis) and defect-management integration (e.g., DefectDojo).
- Experience with commercial AppSec/SCA platforms such as Wiz Code, Veracode, Checkmarx, Cycode, or SonarQube.
- Experience developing and operationalizing a vulnerability management or product security program at scale.
- Experience with industry frameworks such as SOC 2, HITRUST, or ISO 27001, and supporting audit/customer-assurance processes.
- Applying ML/AI techniques to enhance security detection, anomaly identification, and automated risk prioritization.
- Relevant security and cloud certifications.
Compensation
Overall Market Range: $114,000 — $240,000 USD
Equal Opportunity Statement
Reltio is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. Reltio is committed to working with and providing reasonable accommodation to applicants with physical and mental disabilities.
$125k - $165k
...economic inclusion. Find out how TripleLift raises up the programmatic ecosystem at triplelift.com. Overview The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's...SuggestedFull timeFlexible hours$150k - $196k
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across...SuggestedTemporary workRemote work$85k - $105k
...Application Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established and...SuggestedFull timeH1bLocal areaImmediate startRemote workVisa sponsorship$98k - $146k
...technologies in support of U.S. National Security and Defense. For the past forty-five... ...require U.S. citizenship for all employees. Applicants that do not meet this requirement will... ...an immediate opportunity for a talented engineer to support our programs delivering Next-...SuggestedTemporary workFor contractorsWork experience placementImmediate startRemote workFlexible hours- Role Description As we scale, so does the trust our customers place in us to protect their data. We're hiring a Senior Application Security Engineer to help harden our platform — from how we isolate workloads and control access, to how we secure our network, harden our...SuggestedFull timeTemporary workImmediate startRemote workFlexible hours
$180k - $200k
...Description Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most... ...core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop...Full timeFlexible hours$100k - $140k
Role Description Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security...Full timeFlexible hours$120k - $145k
Role Description Parallels is seeking a highly motivated and talented Application Security Engineer to join our team. In this role, you will make security decisions that impact millions of our customers while gaining hands-on experience in exploit development and CVE discovery...Full timeRemote work- Role Description As a Senior Application Security Engineer, you’ll help shape the future of our AppSec program. You’ll work effectively and efficiently in a small, high-impact team, bringing a sense of ownership and community. You’ll have the opportunity to learn quickly...Full timeFlexible hours
$150k - $196k
Role Description The Senior Application Security Engineer joins the Information Security team and plays a key role in securing the OneStream platform throughout the software development lifecycle. This role is responsible for: ~Defining and enforcing secure coding and...Full timeTemporary work- Role Description BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering...Full timeRemote work
$180k - $205.5k
Role Description Spring Health is looking for a Senior Application Security Engineer II to join our growing Application Security team. Reporting to the Manager, Application Security, you will play a key role in maturing and expanding our AppSec programs — including established...Full timeWork experience placementRemote workSleeping nights- Role Description The primary responsibility of the Senior Application Security Engineer (AI-First Development) is to design, orchestrate, and validate the offensive security tooling and adversary-emulation capabilities used to find, prove, and help remediate exploitable...Full timeFlexible hours
- Role Description Our team is growing and we're hiring a Senior Application Security Engineer to join our engineering team and enable our next phase of growth. Canary's engineering team is fully remote! This role focuses on embedding security into the software development...Full timeRemote work
$180k - $210k
Role Description We're hiring a Senior Application Security Engineer to join a small, high-leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: ~Set the technical direction and own delivery on how we find, fix, and prevent vulnerabilities...Full timeFlexible hours$100k - $130k
Role Description As a Senior Application Security Engineer at Bonterra, you will be embedded across the Engineering organization, partnering directly with development teams to drive vulnerability remediation, build security ownership, and close the gap between identified...Full timeLocal areaImmediate start$180k - $215k
Role Description Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering...Full timeWork at officeRemote workWeekend work$100k - $150k
Role Description We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with... ...lunch-and-learns, and onboarding content for engineering staff. ~Respond to security incidents involving application...Full timeLocal areaImmediate start$130k - $190k
...be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50... ...this role now: The company is maturing its application security function from a position of strength...Full timeHome office$111k - $144.4k
Role Description The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected...Full timeTemporary workWork experience placement$192k - $240k
Role Description As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will: ~Perform code reviews, design reviews, penetration testing, and vulnerability management....Full timeWork experience placement$125.6k - $172.7k
Role Description As an Application Security Engineer at Solventum, you will: ~Join a team of cybersecurity professionals motivated to secure Solventum's healthcare information systems and the personal health information of our clients and their patients. ~Operate and...Full timeFlexible hours- Role Description The Application Security Engineer plays a crucial role in securing our growing portfolio of applications. This role will focus on integrating security best practices into the Software Development Lifecycle (SDLC), ensuring compliance with regulatory requirements...Full time
- Role Description As an Application Security Engineer at Oneleet, you'll bring security depth to our product engineering teams as we expand our cybersecurity platform. You'll own the security judgment layer that sits between raw tooling output and what our customers actually...Full timeRemote work
- Role Description DecisionPoint seeks an Application Security Engineer to perform advanced application-layer security assessments, secure coding reviews, vulnerability analysis, and security integration for enterprise applications supporting a federal and DoD-aligned mission...Full timeLocal areaRemote work
- Role Description GuidePoint Security offers an inclusive set of Application Security services helping clients implement, fine tune and run their Application Security SAST, DAST and SCA tools. Many clients need assistance with either supplementing their Application Security...Full timeRemote workFlexible hours
$190k - $273k
Role Description The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends...Full timeFlexible hours$120k - $258.5k
Role Description Nordstrom is building a new Application Security team, built on a simple idea: teams shouldn’t have to choose between moving... ...of Application Security and partner closely with product engineering and DevOps, alongside our security peers in pentest, attack...Full time$157k - $216k
...investing in the next generation of our Application Security capability, a continuous, AI-augmented... ...defense program built for a SaaS engineering organization where AI agents and human... ...foundational hire with a clear path to Staff / Tech Lead as the team grows. Qualifications...Full timeRemote work$175k - $215k
Role Description We're looking for an Application Security Engineer to help build secure-by-default products and services across Quanata's AI-native insurance technology platform. In this role, you'll partner closely with Product, Engineering, and Security teams to identify...Extra incomeFull timeHome officeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Application Security Engineer. Be the first to apply!
- staff security engineer Remote
- project engineer assistant project manager Remote
- assistant chief engineer Remote
- staff data engineer Remote
- senior staff engineer Remote
- staff design engineer Remote
- engineering aide Remote
- software engineer staff Remote
- assistant engineer Remote
- assistant engineering manager Remote















