Staff Application Security Engineer
$20kServiceTitan
Ready to be a Titan? At ServiceTitan, we are transforming product security into a core part of how engineering delivers software. We are looking for an exceptional Staff Application Security Engineer to help us build a "Secure Paved Road"-an automated, self-service ecosystem that enables our 80+ R&D squads to build securely by default. This role will define and scale how secure software is built at ServiceTitan by embedding security directly into the development lifecycle, from code to production. It will reduce organizational risk by automating detection and remediation of vulnerabilities, standardizing secure architecture patterns, and eliminating entire classes of security issues at their source. By partnering closely with engineering, this role will drive a shift toward secure by default development while continuously validating defenses through testing, threat modeling, and proactive simulation. What you'll do:
Build the Secure Paved Road (Pipeline and Code)
Use of AI Technology: We use technology, including automated and AI-assisted tools, to support certain aspects of our recruitment process. These tools are designed to improve efficiency and enhance the candidate experience. AI tools are not used to make hiring decisions; all hiring decisions are made by our hiring teams. What We Offer:
When you join our team, you're not just accepting a job. You're making a career move. Here's how we'll support you in doing some of the most impactful work of your career:
Build the Secure Paved Road (Pipeline and Code)
- Pipeline Automation: Deeply integrate GitHub Advanced Security into the CI/CD pipeline to act as automated checkpoints, providing fast feedback to engineers without manual intervention.
- Secure by Default Code: Collaborate with Engineering to develop and maintain secure microservice templates and libraries with embedded security controls.
- Secrets and Supply Chain: Lead hardcoded secrets mitigation efforts by automating detection and building workflows to validate compromised credentials via API.
- Secure SDLC Practices: Drive cross functional initiatives to establish and continuously improve secure software development lifecycle practices across the organization.
- Penetration Testing: Lead onboarding and operation of continuous penetration testing capabilities across web applications and services.
- Security Assessments: Participate in and help scale internal security assessments, penetration testing, and bug bounty programs.
- Tooling Ownership: Evaluate, prototype, implement, and operate security tools including DAST, SAST, and SCA.
- Simulation and Validation: Run proactive simulations based on emerging threats to validate defenses and identify gaps.
- Security Design Reviews: Lead security design reviews and threat modeling for new and existing services.
- Secure Architecture: Develop and maintain secure architecture standards, frameworks, and reusable patterns across multiple layers of the stack.
- Emerging Threat Analysis: Continuously analyze evolving security threats, determine relevance, and implement centralized mitigations.
- Technical Leadership: Act as the AppSec technical expert for the Security Champions Program, guiding engineers on vulnerability remediation and secure coding practices.
- Contextual Training: Implement just in time training mechanisms that help engineers remediate vulnerabilities as they are introduced.
- Triage to Automate: Own initial triage of vulnerability findings, identify patterns, and drive automation and guardrails to reduce recurring issues.
- Incident Response: Participate in security incident response and support post incident analysis and remediation efforts.
- Maintain strong knowledge of current security threats, vulnerabilities, and operational best practices, applying that knowledge to continuously improve the organization's security posture.
- Experience: 7-10+ years of experience in Product/Application Security, with a strong background in software engineering.
- Coding Expertise: Proficiency in C#/.NET (preferred) or Go/Java. You must be able to read code to find vulnerabilities and write code to fix them.
- Modern AppSec: Experience moving security "left" using tools like GitHub Advanced Security (GHAS), dependency scanners, and secret detectors.
- Automation Mindset: Proven ability to script (Python, Go, PowerShell) and automate security tasks. You prefer building a tool to solve a problem over fixing it manually.
- AI Forward: Interest in the intersection of AI and Security, specifically in securing AI workloads, leveraging AI capabilities to embed security throughout the SDLC, and using AI agents for defense.
Use of AI Technology: We use technology, including automated and AI-assisted tools, to support certain aspects of our recruitment process. These tools are designed to improve efficiency and enhance the candidate experience. AI tools are not used to make hiring decisions; all hiring decisions are made by our hiring teams. What We Offer:
When you join our team, you're not just accepting a job. You're making a career move. Here's how we'll support you in doing some of the most impactful work of your career:
- Flextime, recognition, and support for autonomous work: Flexible time off with ample learning and development opportunities to continue growing your career. We offer a comprehensive onboarding program, leadership training for Titans at all levels, and other programs and events. Great work is rewarded through Bonusly, peer-nominated awards, and more.
- Holistic health and wellness benefits : Company-paid medical, dental, and vision (with 100% employer paid options and 90% coverage for dependents), FSA and HSA, 401k match, and telehealth options including memberships to One Medical.
- Support for Titans at all stages of life : Parental leave and support, up to $20k in fertility services (i.e. IUI and IVF), surrogacy, and adoption reimbursement, on demand maternity support through Maven Maternity, free breast milk shipping through Maven Milk, pet insurance, legal advisory services, financial planning tools, and more.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Staff Application Security Engineer in United States vacancy
$150.2k - $225.4k
...About the team: The Information Security organization advances the overall state of security at Rubrik through purposeful... ...information. About the role: Rubrik is seeking an Application Security Engineer. In this role, you will be responsible for ensuring that...SuggestedWork experience placementLocal areaRemote workShift work$160k - $240k
...Application Security Engineer Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to...SuggestedRemote workHome officeFlexible hours- ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a... ...and more. Who we're looking for: We are seeking an Application Security Engineer with expertise in Static and Dynamic Application Security...SuggestedContract workRemote work
$110k
...Job Seekers can review the Job Applicant Privacy Policy by clicking here ( . Job Description : SUMMARY We seek a highly motivated and experienced Application Security Engineer to join our growing security team. This role is highly technical and candidates...SuggestedFull time- ...seeking a professional to be an integral component of the application security program end-to-end - from discovery and inventory of business... ...in application security, product security, or security engineering, with at least 3 years in environments with multiple independent...SuggestedWork experience placementImmediate start
- ...The details are below. Beware of scams. S3 never asks for money during its onboarding process. Job Title: Senior Application Security Engineer (AI/ML) Contract Length: 6+ months Location: Iselin NJ 08830/ Charlotte, NC/ Dallas, TX/ Phoenix, AZ 3 days onsite...Contract workRemote workVisa sponsorshipShift work3 days per week
- ...Senior Application Security Engineer A new space race has begun. True Anomaly seeks those with the talent and ambition to build innovative technology that solves the next generation of engineering, manufacturing, and operational challenges for space security and sustainability...Shift work
$60 - $65 per hour
...Application Security Engineer Location: Phoenix, AZ 85054 (Atlanta GA, or NY, NY) (Onsite/Hybrid) Pay Rate: $60.00 - $65.00 per hour (Strict W2 Only) Duration: Through 12/31/2026 + Long-term Extension Compliance: No C2C, Third Parties, or W2 Referrals Role...Hourly payWeekly payTemporary workFlexible hours- ...Senior Application Security Engineer Location: Middletown, NJ (F2F Required, Onsite from Day Telecom Experience) Long Term Overview: We are looking for a Senior Application Security Engineer to join our growing team and play a hands-on role in strengthening security...
$213k
...Senior Application Security Engineer Remote, USA; San Francisco, CA, USA About the Role We are looking for a Sr. Full Stack Application Security Engineer with deep expertise in mobile application security to join our Product Security team. This role is hands-on...Full timeWork at officeLocal areaRemote workNight shift- ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software...Full time
- ...Application Security Engineer The Application Security Engineer will be responsible for analyzing software code repositories, code designs, processes... ...interpersonal skills, with the ability to enable fellow staff through training, communication and mentorship Problem...
- ...TX ( Candidate must be local to any of these locations ) Hybrid from day-1 Description : Sr. Application Security Engineer Job Summary: This role focuses on comprehensive application security testing and vulnerability management...Local area
$135k - $200k
...defense, intelligence, and commercial applications. We are trusted by our customers to protect... .... The mission of the Application Security Team is to enable developers to be highly... ...important. As an Application Security Engineer, you will be hands-on and have wide-...Work experience placementWork at officeRemote workWork from homeRelocation package$205k - $275k
...Application Security Engineer Opportunity We're hiring an Application Security Engineer to work hands-on with our engineering teams to find and fix vulnerabilities, harden our applications, and keep security woven into how we build software. This is a practitioner role...Home officeFlexible hours- ...Job Title: Application Security Engineer Location: Remote Duration: Fulltime Skills: System Z Salary: 100K-120K/Year Roles and Responsibilities: Must Have Technical/Functional Skills Candidate must be a Leader with hands-on engineer...Full timeRemote work
- ...Job Title: Application Security Engineer (DevSecOps) Location: Onsite 5x/Week in Plano, TX Type: Direct Hire Top 3-5 Must Have Skills for the Position: Practical experience with AI-assisted coding and agentic code (e.g., using GitHub Copilot, Claude...Extra income
- ...Opal Security Application Security Engineer At Opal, we're building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex...Remote work
$180k - $220k
...Senior Application Security Engineer, AI and Machine Learning San Francisco, California, United States; Seattle, Washington, United States Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing...Work at officeWork from homeFlexible hours2 days per week$130k - $280k
...platform that includes solutions for video security, access control, air quality sensors,... ...Facilitate the security baked into our applications throughout the software development... ...information sharing Partner closely with engineering and product teams to improve the...Full timeWork visaFlexible hoursShift work$200k - $245k
...founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence... ...and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security...Full timeWork at officeWorldwide- ...UK, Europe, Japan and Canada, and has been used for more than 500,000 patients worldwide. We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC)....Work at officeLocal areaWorldwideRelocation3 days per week
$180k - $210k
...Senior Application Security Engineer At Qualia, we've built the leading B2B real estate technology that transforms the home buying and selling... ...leverage AppSec team. This is a deep-technical IC role with a staff-leaning scope: you'll set the technical direction and own...Work at officeRemote workFlexible hours- ...Application Security Engineer On behalf of our Financial Services client, Procom is searching for an Application Security Engineer for a 12-month role. This position is a hybrid position with 4 days onsite at our client's Southlake, TX office. Alternative locations...Contract workWork at officeImmediate startRemote work
- ...Application Security Engineer Application Security Engineer with DAST & SAST experience with scripting knowledge (JS, Python) Conducting Static Application Security Testing (SAST) using industry-leading tools such as Checkmarx, Veracode, and Fortify. Collaborating...
$130k - $180k
...physicians, providing critical information about the right treatments for the right patients, at the right time. Senior Application Security Engineer Tempus is seeking a Senior Application Security Engineer with deep expertise in penetration testing to join our...- ...Application Security Engineer Bright Vision Technologies is a forward-thinking software development company dedicated to building innovative solutions... ...lunch-and-learns, and onboarding content for engineering staff. Respond to security incidents involving application...Full timeH1bImmediate startRemote workVisa sponsorship
- ...Job Description We are looking for an Application Security Engineer to work for our client. The ideal candidate aligns with the responsibilities and qualifications outlined below. This is a high-impact opportunity to join a growing security function focused on...
- ...Because at Valence, the work worth doing is the kind that redefines work itself. The Role We are seeking a seasoned Application Security Engineer to help us secure our products and platform that serve our Fortune 500 customers. In this pivotal role, you will be...Full timeFreelanceWork from home
$67.67 - $112.78 per hour
...Job Description Title : Senior Application Security Engineer Location : Brooklyn Park, MN Job Type : Contract (12 Months) Compensation : $67.67 - $112.78/hr Industry: Retail --- About the Role We are partnering with a leading...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Application Security Engineer. Be the first to apply!
Related searches
- staff security engineer United States
- staff devops engineer United States
- assistant engineer United States
- assistant process engineer United States
- engineering aide United States
- assistant field engineer United States
- assistant chief engineer United States
- engineering administrative assistant United States
- staff engineer United States
- staff process engineer United States

