Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer

Brain Trust Inc

Application Security Engineer

We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted environments, with open source libraries embedded inside thousands of customer applications and a model proxy in front of major model providers.

This is a hands-on IC role. You'll review code, build threat models, ship paved-road libraries, and lead AI-specific security work: prompt injection, agent sandbox escapes, tool-use abuse, and the new attack surface that comes with LLM-native applications. If you reach for agentic coding tools as your default workflow and can hold your own in a design review with a backend or systems engineer, we'd love to work with you.

What You'll Do
  • Drive secure design across the platform: lead threat models for new features, review architecture proposals, and partner with product and backend engineers to ship features that are secure by default

  • Review code across our TypeScript, Python, and Go services, our open source tracing libraries, and our model proxy — and find the bugs others miss

  • Build the paved road: authn/authz primitives, RBAC and tenancy isolation patterns, secret handling, safe data pipelines, and sandboxed code execution for user-supplied JavaScript and Python snippets

  • Own our SAST, DAST, SCA, and secret-scanning tooling end-to-end, keeping signal-to-noise high enough that engineers actually fix what you ship

  • Run our vulnerability management program and triage external bug bounty reports; close the loop with durable fixes, not point patches

  • Lead AI-specific security work: prompt injection defenses, model proxy abuse detection, agent and tool-use sandboxing, data-exfiltration controls in multimodal pipelines, and security for the eval workflows our customers run

  • Partner with our open source maintainers on the security of libraries that get embedded inside customer applications

  • Use agentic coding workflows to scale yourself: automated code review, exploit prototyping, control validation, and IR triage

Ideal Candidate Credentials
  • 5+ years in application security, product security, or backend engineering with a security focus — you've shipped real code and reviewed a lot of it

  • Strong code reading and writing skills in at least two of TypeScript/Node.js, Python, Go, or Rust

  • Deep knowledge of common web and API vulnerability classes and the architectural patterns that prevent them — not just OWASP Top 10 trivia

  • Track record of building secure-by-default libraries, frameworks, or services that other engineers actually adopt

  • Hands-on experience with authn/authz design, multi-tenant data isolation, and secrets/key management at scale

  • Comfortable with the realities of a high-availability data platform: real-time pipelines, ingestion at scale, semi-structured data, Postgres, Redis, AWS

  • A clear point of view on AI/LLM security — prompt injection, agent abuse, tool-use sandboxing, model proxy threats — and ideally hands-on experience defending against them

  • Daily user of agentic coding tools and excited to push the frontier of how AppSec gets done with them

  • Clear communicator who documents decisions, writes tickets engineers want to pick up, and lifts the team's security awareness without becoming a bottleneck

  • Bonus: prior experience with LLM red-teaming, agent sandbox research, or shipping security-focused open source libraries

Benefits Include
  • Medical, dental, and vision insurance

  • Daily lunch, snacks, and beverages

  • Flexible time off

  • Competitive salary and equity

  • AI Stipend

Equal Opportunity

Braintrust is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Application Security Engineer in Washington DC vacancy
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Suggested
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Washington DC
    5 days ago
  • Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation...  ...innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle. Job... 
    Suggested

    Bloomberg Industry Group

    Arlington, VA
    2 days ago
  •  ...Community Service and Employee Engagement events are atop our calendar events! MBL Technologies is seeking an experienced Application Security Engineer to support the security and integrity of enterprise applications within a federal environment. This role will focus on... 
    Suggested
    Full time
    Remote work

    MBL Technologies

    Washington DC
    1 day ago
  •  ...AI Systems Security Specialist Client added a crucial skill that they are seeking expertise in here is securing AI systems...  ...AWS cloud security architecture and services Cloud application security engineering Docker and Kubernetes security Infrastructure as Code... 
    Suggested

    RIT Solutions

    Washington DC
    2 days ago
  • $62k - $141k

     ...Application Security Engineer The Opportunity: Work together with the client and application community to maintain a resilient security posture for highly visible applications. Remediate application security flaws in conjunction with the application security team... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    5 days ago
  •  ...VA Contract What You'll Do: Collaborate with a team of engineers to implement *** specific security policies in the CI/CD security tools including but not limited to SAST, DAST and SCA applications. Work with Development, DevOps and Security teams to... 
    Contract work
    Work experience placement

    US Tech Solutions

    Arlington, VA
    5 days ago
  •  ...Application Security Engineer Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise... 

    Comtech LLC

    Washington DC
    2 days ago
  •  ...already outstanding team. Accenture Security helps organizations prepare, protect, detect...  ..., digital identity, cyber defense, application security and managed service solutions to...  ...is seeking an experienced Lenel OnGuard Engineer / Application Support Consultant to support... 
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Arlington, VA
    1 day ago
  • $110k

    Job Description We seek a highly motivated and experienced Application Security Engineer to join our growing security team. This role is highly technical and candidates must possess a solid understanding of the security and privacy of our company's applications and data... 
    Full time

    Ryder System, Inc.

    Washington DC
    2 days ago
  • SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This... 

    SourcePro Search

    Washington DC
    5 days ago
  •  ...the lifecycle of supply chain risk, bringing speed and clarity to enterprise response. Job Overview: The Application Security Engineer will secure Interos.ai's AWS cloud environments, containerized workloads, application stack, CI/CD pipelines, and... 

    RIT Solutions, Inc.

    Washington DC
    2 days ago
  • A leading security solutions firm is seeking a Senior Application Security Engineer in Washington, DC. The ideal candidate will integrate secure design in application development and collaborate on security solutions. They should have extensive experience in cybersecurity... 

    SourcePro Search

    Washington DC
    5 days ago
  • Ernst & Young Oman seeks an Application Security Engineer to enhance security tools and manage development platforms. You will collaborate with teams to integrate security processes and automate deployments while ensuring optimal security measures throughout the software... 

    Ernst & Young Oman

    Washington DC
    3 days ago
  • Ernst & Young Oman is hiring an Application Security Engineer in Arlington, Virginia. The role involves managing application development platforms and optimizing security tools while ensuring operational efficiency through automation. Ideal candidates should have a relevant... 
    Flexible hours

    Ernst & Young Oman

    Arlington, VA
    3 days ago
  • $100k - $155k

    Overview As an Application Security Engineer , you will provide technical expertise and solutions to remediate persistent and challenging portfolio-wide vulnerabilities. We’re looking for someone who has passion for IT, resourceful problem‑solving abilities, and a desire... 

    Steampunk

    Mc Lean, VA
    1 day ago
  • $120k - $140k

     ...Application Security Engineer Location: Fully Remote (East Coast) Clearance: Public Trust, Secret Clearance preferred Employment Type: Full-time Salary: $120,000-$140,000 Role Overview : The Application Security Engineer will support the secure development... 
    Full time
    Remote work

    TOMORROW HIRE

    Washington DC
    20 days ago
  • $100k - $155k

    Steampunk is seeking an Application Security Engineer in McLean, Virginia. This role involves providing expertise to remediate vulnerabilities and uphold security practices across enterprise applications. Ideal candidates need to have experience in application security... 

    Steampunk

    Mc Lean, VA
    5 days ago
  • $77.5k - $140.9k

     ...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application development platforms and optimizing security tools to... 
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Washington DC
    3 days ago
  • SourcePro Search is seeking a Mid-Level Application Engineer - Cyber Security Analytics Engineer in Washington, DC. The ideal candidate will develop and manage software tools to support Enterprise Management, focusing on software specifications, program design, and documentation... 

    SourcePro Search

    Washington DC
    3 days ago
  • We are conducting a search for a Mid‑Level Application Engineer - Cyber Security Analytics Engineer. We are seeking an ideal candidate who can develop and manage software tools to support Enterprise Management. This role involves formulating and defining specifications... 

    SourcePro Search

    Washington DC
    3 days ago
  • $105k - $130k

     ...government and nonprofit organizations and individuals. Applications Engineer The Applications Engineer is a highly skilled technical position...  ...project work with minimal supervision, ensuring stable, secure, and scalable application solutions aligned with business... 
    Temporary work
    Work at office
    Remote work

    Katten Muchin Rosenman LLP

    Washington DC
    1 hour ago
  • $118.72k - $190.04k

     ...Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance...  ...not limited to job location, experience, applicable skills and training, external market... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Work from home
    Worldwide
    Flexible hours

    Red Hat

    Washington DC
    3 days ago
  •  ...Product Security Engineer Gecko Robotics is helping the world's most important organizations ensure the availability, reliability, and...  ...We are building the Product Security team to build and scale application security at Gecko. As a Product Security Engineer you will play... 
    Work at office
    Local area
    Work from home
    Flexible hours

    Gecko Robotics Inc

    Washington DC
    2 days ago
  • $130k - $150k

     ...the ultimate goal of enabling human life on Mars. PRODUCT SECURITY ENGINEER (STARSHIELD) Starshield leverages SpaceX’s Starlink...  ...immediately necessary upon hire, we encourage you to initiate the application process promptly upon accepting this offer. Your ability to... 
    Permanent employment
    Temporary work
    Immediate start
    Flexible hours
    Weekend work

    SpaceX

    Washington DC
    4 days ago
  • $140k - $165k

     ...Senior Product Security Engineer Uplight is creating a new category of energy. We make software that manages energy resources in homes...  ...bring to Uplight: Advanced experience in securing applications and application settings Advanced experience in app and... 
    Local area
    Flexible hours
    Shift work

    upLIGHT

    Washington DC
    2 days ago
  •  ...Title: Senior Application Developer/Engineer/Programmer Location: Washington, DC Job Description The Senior Information Systems Specialist provides advanced support for enterprise information systems, including analysis, integration, and administration... 

    Apex Informatics

    Washington DC
    1 day ago
  • $133k - $166k

     ...What You'll Do We are seeking a Senior Application Engineer I to lead the advanced configuration, integration, and optimization...  ...vendors, and internal stakeholders to ensure applications are secure, scalable, and fully leveraged to meet complex business needs... 
    Worldwide
    Flexible hours

    Kirkland & Ellis

    Washington DC
    1 day ago
  • $107.63k

     ...Posting Title Application Engineer II Overview Application Engineer II in Washington, D.C. Application development, integration, maintenance...  .... Participate in new functionality development to ensure secure, elegant and low maintenance date designs are adopted. Email... 

    Catholic University

    Washington DC
    2 days ago
  • $146k - $150k

     ...Suvi is seeking an Applications Engineer III in Washington, DC. The applications developer will design, develop and maintain the FBI's Electronic...  ...technologies that accomplish customers' missions safely, securely, and efficiently. As a Suvi employee , you will be... 
    Full time
    Part time
    For contractors
    Local area
    Remote work

    NANA Regional Corp

    Washington DC
    2 days ago
  •  ...Application Engineer Project Overview: Professional services engagement: implement advanced features within their software, specifically Wealth and Retirement suite of products--Omni2 Suite: large record-keeping system for pension plans, 401k, etc. Has 13-15 surrounding... 

    Software Technology Inc

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!