Application Security Engineer
Brain Trust Inc
Application Security Engineer
We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted environments, with open source libraries embedded inside thousands of customer applications and a model proxy in front of major model providers.
This is a hands-on IC role. You'll review code, build threat models, ship paved-road libraries, and lead AI-specific security work: prompt injection, agent sandbox escapes, tool-use abuse, and the new attack surface that comes with LLM-native applications. If you reach for agentic coding tools as your default workflow and can hold your own in a design review with a backend or systems engineer, we'd love to work with you.
What You'll Do
Drive secure design across the platform: lead threat models for new features, review architecture proposals, and partner with product and backend engineers to ship features that are secure by default
Review code across our TypeScript, Python, and Go services, our open source tracing libraries, and our model proxy — and find the bugs others miss
Build the paved road: authn/authz primitives, RBAC and tenancy isolation patterns, secret handling, safe data pipelines, and sandboxed code execution for user-supplied JavaScript and Python snippets
Own our SAST, DAST, SCA, and secret-scanning tooling end-to-end, keeping signal-to-noise high enough that engineers actually fix what you ship
Run our vulnerability management program and triage external bug bounty reports; close the loop with durable fixes, not point patches
Lead AI-specific security work: prompt injection defenses, model proxy abuse detection, agent and tool-use sandboxing, data-exfiltration controls in multimodal pipelines, and security for the eval workflows our customers run
Partner with our open source maintainers on the security of libraries that get embedded inside customer applications
Use agentic coding workflows to scale yourself: automated code review, exploit prototyping, control validation, and IR triage
Ideal Candidate Credentials
5+ years in application security, product security, or backend engineering with a security focus — you've shipped real code and reviewed a lot of it
Strong code reading and writing skills in at least two of TypeScript/Node.js, Python, Go, or Rust
Deep knowledge of common web and API vulnerability classes and the architectural patterns that prevent them — not just OWASP Top 10 trivia
Track record of building secure-by-default libraries, frameworks, or services that other engineers actually adopt
Hands-on experience with authn/authz design, multi-tenant data isolation, and secrets/key management at scale
Comfortable with the realities of a high-availability data platform: real-time pipelines, ingestion at scale, semi-structured data, Postgres, Redis, AWS
A clear point of view on AI/LLM security — prompt injection, agent abuse, tool-use sandboxing, model proxy threats — and ideally hands-on experience defending against them
Daily user of agentic coding tools and excited to push the frontier of how AppSec gets done with them
Clear communicator who documents decisions, writes tickets engineers want to pick up, and lifts the team's security awareness without becoming a bottleneck
Bonus: prior experience with LLM red-teaming, agent sandbox research, or shipping security-focused open source libraries
Benefits Include
Medical, dental, and vision insurance
Daily lunch, snacks, and beverages
Flexible time off
Competitive salary and equity
AI Stipend
Equal Opportunity
Braintrust is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
$40 per hour
...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback... ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some...SuggestedHourly payFull timePart timeRemote work- Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation... ...innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle. Job...Suggested
- ...Community Service and Employee Engagement events are atop our calendar events! MBL Technologies is seeking an experienced Application Security Engineer to support the security and integrity of enterprise applications within a federal environment. This role will focus on...SuggestedFull timeRemote work
- ...AI Systems Security Specialist Client added a crucial skill that they are seeking expertise in here is securing AI systems... ...AWS cloud security architecture and services Cloud application security engineering Docker and Kubernetes security Infrastructure as Code...Suggested
$62k - $141k
...Application Security Engineer The Opportunity: Work together with the client and application community to maintain a resilient security posture for highly visible applications. Remediate application security flaws in conjunction with the application security team...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- ...VA Contract What You'll Do: Collaborate with a team of engineers to implement *** specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications. Work with Development, DevOps and Security teams to...Contract workWork experience placement
- ...Application Security Engineer Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise...
- ...already outstanding team. Accenture Security helps organizations prepare, protect, detect... ..., digital identity, cyber defense, application security and managed service solutions to... ...is seeking an experienced Lenel OnGuard Engineer / Application Support Consultant to support...Work experience placementLive inWork at officeLocal area
$110k
Job Description We seek a highly motivated and experienced Application Security Engineer to join our growing security team. This role is highly technical and candidates must possess a solid understanding of the security and privacy of our company's applications and data...Full time- SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This...
- ...the lifecycle of supply chain risk, bringing speed and clarity to enterprise response. Job Overview: The Application Security Engineer will secure Interos.ai's AWS cloud environments, containerized workloads, application stack, CI/CD pipelines, and...
- A leading security solutions firm is seeking a Senior Application Security Engineer in Washington, DC. The ideal candidate will integrate secure design in application development and collaborate on security solutions. They should have extensive experience in cybersecurity...
- Ernst & Young Oman seeks an Application Security Engineer to enhance security tools and manage development platforms. You will collaborate with teams to integrate security processes and automate deployments while ensuring optimal security measures throughout the software...
- Ernst & Young Oman is hiring an Application Security Engineer in Arlington, Virginia. The role involves managing application development platforms and optimizing security tools while ensuring operational efficiency through automation. Ideal candidates should have a relevant...Flexible hours
$100k - $155k
Overview As an Application Security Engineer , you will provide technical expertise and solutions to remediate persistent and challenging portfolio-wide vulnerabilities. We’re looking for someone who has passion for IT, resourceful problem‑solving abilities, and a desire...$120k - $140k
...Application Security Engineer Location: Fully Remote (East Coast) Clearance: Public Trust, Secret Clearance preferred Employment Type: Full-time Salary: $120,000-$140,000 Role Overview : The Application Security Engineer will support the secure development...Full timeRemote work$100k - $155k
Steampunk is seeking an Application Security Engineer in McLean, Virginia. This role involves providing expertise to remediate vulnerabilities and uphold security practices across enterprise applications. Ideal candidates need to have experience in application security...$77.5k - $140.9k
...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application development platforms and optimizing security tools to...Summer holidayFlexible hours- SourcePro Search is seeking a Mid-Level Application Engineer - Cyber Security Analytics Engineer in Washington, DC. The ideal candidate will develop and manage software tools to support Enterprise Management, focusing on software specifications, program design, and documentation...
- We are conducting a search for a Mid‑Level Application Engineer - Cyber Security Analytics Engineer. We are seeking an ideal candidate who can develop and manage software tools to support Enterprise Management. This role involves formulating and defining specifications...
$105k - $130k
...government and nonprofit organizations and individuals. Applications Engineer The Applications Engineer is a highly skilled technical position... ...project work with minimal supervision, ensuring stable, secure, and scalable application solutions aligned with business...Temporary workWork at officeRemote work$118.72k - $190.04k
...Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance... ...not limited to job location, experience, applicable skills and training, external market...Permanent employmentFull timeContract workWork experience placementWork at officeRemote workWork from homeWorldwideFlexible hours- ...Product Security Engineer Gecko Robotics is helping the world's most important organizations ensure the availability, reliability, and... ...We are building the Product Security team to build and scale application security at Gecko. As a Product Security Engineer you will play...Work at officeLocal areaWork from homeFlexible hours
$130k - $150k
...the ultimate goal of enabling human life on Mars. PRODUCT SECURITY ENGINEER (STARSHIELD) Starshield leverages SpaceX’s Starlink... ...immediately necessary upon hire, we encourage you to initiate the application process promptly upon accepting this offer. Your ability to...Permanent employmentTemporary workImmediate startFlexible hoursWeekend work$140k - $165k
...Senior Product Security Engineer Uplight is creating a new category of energy. We make software that manages energy resources in homes... ...bring to Uplight: Advanced experience in securing applications and application settings Advanced experience in app and...Local areaFlexible hoursShift work- ...Title: Senior Application Developer/Engineer/Programmer Location: Washington, DC Job Description The Senior Information Systems Specialist provides advanced support for enterprise information systems, including analysis, integration, and administration...
$133k - $166k
...What You'll Do We are seeking a Senior Application Engineer I to lead the advanced configuration, integration, and optimization... ...vendors, and internal stakeholders to ensure applications are secure, scalable, and fully leveraged to meet complex business needs...WorldwideFlexible hours$107.63k
...Posting Title Application Engineer II Overview Application Engineer II in Washington, D.C. Application development, integration, maintenance... .... Participate in new functionality development to ensure secure, elegant and low maintenance date designs are adopted. Email...$146k - $150k
...Suvi is seeking an Applications Engineer III in Washington, DC. The applications developer will design, develop and maintain the FBI's Electronic... ...technologies that accomplish customers' missions safely, securely, and efficiently. As a Suvi employee , you will be...Full timePart timeFor contractorsLocal areaRemote work- ...Application Engineer Project Overview: Professional services engagement: implement advanced features within their software, specifically Wealth and Retirement suite of products--Omni2 Suite: large record-keeping system for pension plans, 401k, etc. Has 13-15 surrounding...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
- application support engineer Washington DC
- senior application security engineer Washington DC
- application engineering manager Washington DC
- project application engineer Washington DC
- network applications engineer Washington DC
- technical application engineer Washington DC
- cnc applications engineer Washington DC
- hydraulic application engineer Washington DC
- application system engineer Washington DC
- application engineer Washington DC


