Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Application Security Engineer

UniUni

Application Security Engineer

UniUni is a late-stage last-mile logistics company moving millions of parcels across the United States and Canada for some of the largest e-commerce platforms in North America. Our technology is cloud-native on AWS. We hold an active ISO 27001 certification and SOC 2 Type II attestation, and security is central to how we operate and how our customers trust us. This role reports to the Information Security Officer and is based in North America (remote with periodic travel to UniUni hubs).

About the Role

We are hiring an Application Security Engineer to be the senior technical anchor for product and platform security at UniUni. You will set the bar for how we build secure software, embed security into our engineering pipelines, and harden our customer-facing products. You will spend your time shoulder-to-shoulder with engineering, not adjacent to it.

This is a hands-on role. You will write code, review code, build tooling, and lead the technically hardest work across application security, DevSecOps and platform security, and product security. You will set standards that scale, but you will also dig into real systems to find real problems and ship real fixes.

What You'll Do

  • Application Security
  • Lead threat modeling on new and existing services, focusing on the systems where the risk is real and the architecture is in motion.
  • Run our secure code review program, including the design of review playbooks, the hardest reviews yourself, and coaching engineers to catch issues earlier.
  • Operate and tune our AppSec tooling stack across SAST, DAST, SCA, and secrets scanning, keeping signal high and noise low.
  • Own the third-party penetration testing program in partnership with the ISO, from scoping through findings triage and fix verification.
  • Drive standards for authentication, authorization, session management, and API security across our products, and engineer the hard parts yourself when needed.

Platform Security and DevSecOps

  • Embed security controls into our CI/CD pipelines so the secure path is the default path: pre-commit checks, build-time scans, signed artifacts, and policy-as-code gates.
  • Harden our cloud workloads on AWS, including container and Kubernetes security, secrets management, and runtime protections.
  • Codify infrastructure security baselines as IaC and policy (e.g., OPA/Conftest, AWS SCPs, Terraform guardrails) and own the rollout across the platform.
  • Partner with the platform team on identity-aware access to infrastructure, including non-human identities, short-lived credentials, and privileged access patterns.

Product Security

  • Engineer enterprise SSO (SAML 2.0 and OpenID Connect) into customer-facing products in support of contractual security commitments to enterprise shippers.
  • Set the technical direction for API security, including authentication, authorization, rate limiting, abuse prevention, and tenant isolation.
  • Drive secure-by-default patterns for data handling in our products, including encryption, key management, and access controls for customer and operational data.
  • Be the senior technical voice in customer security reviews when the questions go past what a questionnaire can answer.

Across All of It

  • Triage and lead response to application and platform security incidents, including root cause analysis and durable fixes.
  • Mentor engineers on secure design and secure coding, and raise the security fluency of the engineering organization through training, office hours, and example.
  • Contribute to ISO 27001 and SOC 2 evidence, control design, and audit readiness for the controls you operate.

Qualifications

  • 8+ building and securing production software, with the last several focused on application security, product security, or DevSecOps as your primary discipline.
  • Deep, demonstrable software engineering ability. You read code fluently across multiple languages, you write production-quality code, and engineers respect your technical judgment.
  • Hands-on experience securing AWS workloads at scale, including IAM, networking, container and Kubernetes security, and IaC (Terraform or equivalent).
  • Working command of modern AppSec tooling (SAST, DAST, SCA, secrets scanning) and how to deploy it in a CI/CD pipeline without grinding delivery to a halt.
  • Strong threat modeling skills and a track record of turning models into shipped controls.
  • Practical experience implementing SAML 2.0 and OpenID Connect, and a clear mental model of identity, session, and authorization design
  • Experience leading the technical response to security incidents in production environments.
  • Ability to influence engineers and engineering leaders without authority. You explain risk in terms that engineers act on, and you partner rather than police.

Nice to Have

  • Experience in logistics, supply chain, marketplaces, or other high-volume transactional businesses.
  • Background contributing to or maintaining open source security tooling.
  • Prior experience supporting ISO 27001 or SOC 2 control design from the engineering side.
  • Offensive security background (CTFs, bug bounty, red team) that informs how you think about defense.
  • Experience hardening LLM-integrated or AI-powered features in production.

Why This Role

This is a senior IC role with real scope. You will set standards that the engineering organization actually adopts because you will have built them, shipped them, and proved they work. You will report to the Information Security Officer in a security function with executive commitment, a live ISO 27001 certification, and an active SOC 2 Type II attestation, and you will have the autonomy and the mandate to make UniUni's products and platform meaningfully more secure.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Staff Application Security Engineer in United States vacancy
  • $96k - $146k

     ...technologies in support of U.S. National Security and Defense. For the past forty-five...  ...require U.S. citizenship for all employees. Applicants that do not meet this requirement will...  ...an immediate opportunity for a talented engineer to support our programs delivering Next-... 
    Suggested
    Temporary work
    For contractors
    Work experience placement
    Immediate start
    Remote work
    Flexible hours

    SciTec

    Princeton, NJ
    6 days ago
  • $120.25k - $181.25k

     ...This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Application Security Engineer (Offensive / Red Team) in United States. This is a unique opportunity for an experienced offensive security professional to play... 
    Suggested
    Remote job
    Full time
    Flexible hours

    jobgether

    United States
    7 days ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Application Security (AppSec) Engineer to join our team in Hanover, MD. The Application Security (AppSec) Engineer will leverage their strong technical background and knowledge to support software assurance... 
    Suggested
    Work at office

    MANTECH

    Hanover, MD
    16 hours ago
  •  ...Senior Security Engineer – Secure Code Review New York, NY On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software development... 
    Suggested
    Full time

    AGS

    New York, NY
    3 days ago
  • $150k - $160k

     ...Senior Cybersecurity Engineer (Application Security) The Senior Cybersecurity Engineer (Application Security) is responsible for protecting our...  ...details to partners and senior leadership, mentor junior staff, and provide technical direction to the program. Job Responsibilities... 
    Suggested
    For contractors
    Work at office
    Remote work
    Flexible hours

    United Natural Foods

    United States
    4 days ago
  • $180k - $225k

     ...Senior Application Security Engineer United States - Remote Opportunity About Us Temporal is an open source programming model that can simplify code, make applications more reliable, and help developers focus on the important things like delivering features faster... 
    Full time
    Temporary work
    Part time
    Remote work
    Work from home
    Home office

    Temporal Technologies

    United States
    2 days ago
  • $67.67 - $112.78 per hour

     ...Job Description Title : Senior Application Security Engineer Location : Remote Job Type : Contract (12 Months) Compensation : $67.67 - $112.78/hr Industry: Retail --- About the Role We are partnering with a leading enterprise... 
    Contract work
    Remote work

    Dahl Consulting

    United States
    2 days ago
  •  ...Senior Application Security Engineer Become a founding member of the Application Security team at CookUnity. You'll work closely with disparate groups inside of CookUnity's engineering organization, ranging from our Infrastructure and Software Engineering teams to ensure... 
    Remote work
    Flexible hours

    CookUnity

    United States
    5 days ago
  •  ...Senior Application Security Engineer We are seeking a highly skilled and proactive Senior Application Security Engineer to join our growing security team. You will be responsible for securing our applications throughout the software development lifecycle (SDLC). This... 
    Remote work

    e.l.f Cosmetics

    United States
    3 days ago
  •  ...Job Title: Senior Application Security Engineer Get AI-powered advice on this job and access more exclusive features. Direct message the job poster from Unisys. Key Skills and Bonuses: Pentest, OWASP, SAST/DAST/IAST. Bonus: LLM, US citizenship preferred, AWS,... 
    Full time

    Unisys

    Rockville, MD
    3 days ago
  • $128k - $181.25k

     ...Senior Application Security Engineer (Offensive / Red Team) At Shutterfly, we make life's experiences unforgettable. We believe there is extraordinary power in the self-expression. That's why our family of brands helps customers create products and capture moments that... 
    Remote work

    Shutterfly

    United States
    1 day ago
  • $160k - $220k

     ...Join to apply for the Senior Application Security Engineer role at Zip The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally... 
    Full time
    Home office
    Flexible hours

    ZIP

    San Francisco, CA
    3 days ago
  •  ...Application Security Engineer Are you looking for a company where your voice is heard? Where you can make a difference? Do you thrive in a fast-paced work environment? Do you wake every morning excited to work with great people and create success together? Then Intermedia... 
    Remote work
    Day shift

    Intermedia Intelligent Communications

    United States
    1 day ago
  • $70.3k - $101.3k

     ...Application Security Engineer The Application Security Engineer is responsible for embedding security throughout the software development lifecycle (SDLC), leading application security testing, and driving vulnerability remediation efforts. At CivicPlus, we strive... 
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours

    CivicPlus

    United States
    1 day ago
  •  ...I have an opportunity for "Application Security Engineer - REMOTE" and I am looking for a candidate who can join Immediately if you are interested, reply to me with your updated resume or if you could refer someone I would really appreciate it. Position : Application... 
    Immediate start
    Remote work

    Navtech

    United States
    3 days ago
  • $157k - $216k

     ...investing in the next generation of our Application Security capability, a continuous, AI-augmented...  ...defense program built for a SaaS engineering organization where AI agents and human...  ...foundational hire with a clear path to Staff / Tech Lead as the team grows. What You... 
    Contract work
    Local area
    Remote work

    AlphaSense, Inc.

    United States
    5 days ago
  •  ...Senior Application Security Engineer Want to work on building out security from the ground up at the leading edge of AI in healthcare globally? We're looking for a very experienced and highly motivated Senior Application Security Engineer to join our team as one of... 
    Hourly pay
    Full time
    Remote work
    Flexible hours

    Abridge

    United States
    18 hours ago
  • $160k

     ...Application Security Engineer We believe talent deserves a human touch. Your application will be read by an actual person who's excited to discover the real you. Location: Remote (United States) | Employment Type: Full-Time About the Role We are looking for... 
    Full time
    Remote work

    New Charter Technologies

    United States
    1 day ago
  •  ...Senior Application Security Engineer Remote RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution... 
    Remote work
    All shifts
    Shift work

    RegScale

    United States
    10 days ago
  • $120k - $140k

     ...Application Security Engineer Location: Fully Remote (East Coast) Clearance: Public Trust, Secret Clearance preferred Employment Type: Full-time Salary: $120,000-$140,000 Role Overview : The Application Security Engineer will support the secure development... 
    Full time
    Remote work

    Tomorrow Hire

    United States
    1 day ago
  • $125k - $140k

     ...nobody gets locked out of the financial system.   The Opportunity We are seeking a talented and motivated Senior Application Security Engineer with a strong background in AWS and DevOps practices. In this role, you will be responsible for ensuringthe security of... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Trueml

    United States
    1 day ago
  •  ...SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This... 

    SourcePro Search

    Washington DC
    3 days ago
  • $125.6k - $172.7k

     ...Application Security Engineer (Solventum) 3M Health Care is now Solventum At Solventum, we enable better, smarter, safer healthcare to improve lives. As a new company with a long legacy of creating breakthrough solutions for our customers' toughest challenges, we... 
    H1b
    Remote work
    Relocation package
    Flexible hours

    Solventum

    United States
    18 hours ago
  •  ...Application Security Engineer AMERISAFE is seeking a detail-oriented, productivity driven professional to add to our Excellence Team. The Application...  ...and demonstrated ability to effectively communicate with staff, co-workers, management, and external personnel... 
    Work experience placement
    Remote work
    Weekend work

    AMERISAFE

    United States
    1 day ago
  • $60 - $62 per hour

     ...talk with your recruiter to learn more. Base pay range $60.00/hr - $62.00/hr Hello We are looking for Senior Application Security Engineers Locations: Hybrid Roles in Charlotte, NC, Westlake, TX, Chandler, AZ and Minneapolis, MN – 3 days Onsite and 2 days... 
    Contract work
    H1b
    Remote work

    Motion Recruitment

    Minneapolis, MN
    3 days ago
  • $5,250 per month

     ...innovative technology-driven B2B payments organization seeking a curious, inquisitive, highly skilled and motivated Senior Application Security Engineer to join our team. Our company values collaboration, creativity, and excellence in delivering cutting-edge solutions to... 
    16 hours
    Full time
    Temporary work
    Local area
    Remote work

    AvidXchange

    United States
    1 day ago
  • $100k - $150k

     ...Application Security Engineer Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions...  ...lunch-and-learns, and onboarding content for engineering staff. Respond to security incidents involving application... 
    Full time
    H1b
    Immediate start
    Remote work
    Visa sponsorship
    Work visa

    Bright Vision Technologies

    United States
    3 days ago
  • $180k - $210k

     ...Senior Application Security Engineer At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling...  ...leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: you'll set the technical direction and own... 
    Work at office
    Remote work
    Flexible hours

    Qualia

    United States
    5 days ago
  •  ...Find out more about our hiring culture: Dream Team Culture Job Description At ZetaChain, we are seeking a dedicated Protocol Security Engineer to play a pivotal role in fortifying the security of our cutting-edge protocol. You will be deeply involved in the development... 
    Contract work
    Remote work
    Home office

    Blockchain Works

    San Francisco, CA
    3 days ago
  •  ...Title: Software and Application Security Engineer Location: Lake Mary, Florida - Fully Remote Need to have good experience in Application security as well as a development Background. We are seeking a Sr Software Engineer to join our progressive information... 
    Remote work

    RIT Solutions Inc/ Tech Dev IT/ Texperts Inc/ConceptsIT, Inc...

    United States
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Application Security Engineer. Be the first to apply!