Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff/Principal Application Security Engineer

Binti Inc

Binti builds software for state and county government agencies, focusing on reinventing social services. We started in child welfare, with the mission of helping every child have a safe, loving, and stable family. To date, we've helped approve more than 100,000 families to foster or adopt, and we support over 49% of the nation's child welfare system. We have expanded our product offerings in child welfare, moving more to the root of the problem, helping families stay together and avoid separation, and are now expanding horizontally across other areas in social services.

Binti is a for-profit, mission-driven software company based in San Francisco, CA. Investors include Founders Fund, First Round Capital, Kapor Capital, and others. We're a team of ~90 people and growing quickly. We care about creating a workplace where everyone feels welcome and can bring their full self to work. We have a huge, ambitious vision to rewire government to be more effective in expanding opportunities for people around the world, and we are looking for mission-driven, high-empathy, high-performance, and low-ego team members to join us on our exciting journey towards that vision.

As Binti's first Principal Security Engineer (Applications focused), reporting to our CTO, you will play a critical role in ensuring the security and integrity of our software applications. You will work alongside Binti's full-stack engineers, contribute to security controls in our software, identify and address potential security vulnerabilities, implement best practices, and uphold secure coding standards.

WHAT YOU WILL DO
  • Conduct Security Assessments: Provide holistic assessments of Binti's security stance, including performing regular security reviews, code audits, penetration testing, and threat modeling to maintain the highest standard of application security.
  • Set Direction: Help Binti chart a specific and pragmatic course of action to achieve a strong security posture. This includes scoping and prioritizing work, determining what levels of investment and risk we should take on given our scale and capacity, contributing to job descriptions and hiring plans for the next team members, and building relationships across teams and with company leadership to effectively communicate and advocate for these goals.
  • Respond To Incidents: Respond promptly to security incidents, collaborate with engineers on-call, and provide detailed post-event analyses. Evaluate the applicability of emergent security concerns through risk rating and assessment (such as OWASP).
  • Improve Security Architecture: In a leadership capacity with the Engineering team, identify, design, and implement technologies to enhance security automation, during the software development lifecycle, within the product itself, and in cloud hosting environments.
  • Set Security Standards: Lead efforts to design and implement secure coding standards and best practices across the development lifecycle, with an eye toward automation, including effective AI tools
  • Share Expertise: Stay up to date on the latest security threats, vulnerabilities, and industry best practices, and ensure the integration of this knowledge into Binti's security strategies. Act as our company's expert on application security matters, providing mentorship to development teams and fostering a scalable, security-aware culture.
  • Represent the Security team to other Binti teams and Binti leadership: Act as a steward of the Binti values. Tell the story of the security team, advertising its good work, and celebrating wins.
SAMPLE PROJECTS
  • Review and implement security patches and hotfixes in production applications.
  • Implement streamlined feedback of security recommendations for new products before launch into the Binti platform.
  • Improve the security of documents and files uploaded and downloaded on the platform.
  • Analysis, scoping, and implementation of security improvements to better protect Personal Health Information and Personally Identifiable Information stored within the product.
  • Improve notification and escalation of security concerns from third parties (such as security researchers).
  • Integration of new and existing logging and alerting systems to centralized and/or decentralized Security Incident and Event Management (SIEM) platforms.
  • Assess backlog of application-specific security tickets and provide recommendations for remediation and
  • Support evidence collection for compliance frameworks such as SOC 2 Type II and HIPAA.
  • In partnership with a vendor, stand up a bug bounty program and drive engagement from external security researchers
  • Drive the timely completion of critical security tasks (e.g. incident remediation follow-ups), sometimes implementing personally, and sometimes overseeing the implementation by full-stack engineers.
WHAT WE LOVE ABOUT YOU
  • Technical Expertise: Proven experience as an Application Security Engineer or in a similar role. Strong technical background with experience in full-stack development, cloud computing, and scalable architecture. Proficiency in one or more OOP coding languages (Ruby, Python, Java, etc) is strongly preferred.
  • Deep Understanding: Strong understanding and knowledge of web application security principles, common vulnerabilities, and best practices.
  • Collaborative Approach: Excellent communication skills with the ability to simply convey complex security concepts to non-technical stakeholders and clearly articulate the relative risks and trade-offs.
  • Product Orientation: Focused on keeping the company secure while ensuring the team can still ship products and deliver value to customers and users.
  • Decisions That Scale: Experience cultivating a security-aware development culture that scales through mentorship and automation.
  • Passion for Social Impact: A genuine interest in leveraging technology to address social challenges, with a strong sense of purpose in improving outcomes for children in need.
  • Drive urgency with intention: A sense of pragmatism, resourcefulness, and focus to advance our security goals with a relatively small team.
  • Big plus - prior experience with GovTech or FedRamp
Final selected candidates who receive a conditional offer of employment may be required to undergo a background and reference check, which could include verification of employment and education, criminal history review, and, where applicable, fingerprinting.

BENEFITS & PERKS
  • An above-market compensation package (salary + equity)
  • Excellent medical, dental, vision, and life insurance - 99% of insurance premiums covered for you + your dependents
  • Flexible vacation time to promote a healthy work-life blend
  • 13 paid holidays; 11 federally observed holidays (including Juneteenth), plus Election Day and the day after Thanksgiving
  • 16 weeks of paid parental bonding leave for the arrival of a newborn or newly placed infant
  • Sick/mental health time separate from vacation days (accrue up to a cap of 80 hours)
  • 4 weeks of sabbatical after 4 years of service at the company
  • 401k, Commuter benefits, FSA, and DCFSA with administration paid for
  • $5,000 annual bonus for employees who volunteer as a CASA (court-appointed special advocates)
  • $2,500 annual reimbursement for ongoing learning and development, with opportunities to attend trainings/conferences, on-site speaker series, and lunch and learns
  • $300 reimbursement for initial office setup
  • $50 a month effective work reimbursement to cover internet, electricity, office setup costs, or lunch/snacks with coworkers
  • Paid jury duty

At Binti, we celebrate having a diverse team and believe our differences make us stronger. Binti is proud to be an equal-opportunity workplace and is an equal-opportunity employer. We welcome all qualified applicants to apply without regard to race, color, religion, gender, sexual orientation, age, national origin, disability, or protected Veteran status.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Staff/Principal Application Security Engineer in San Francisco, CA vacancy
  • $160k - $220k

     ...driving incredible value for our customers. Join us! The Security team at Zip is responsible for protecting the confidentiality and integrity of our customers’ data. As our first Application Security Engineer, you will take on a dynamic and high impact role. You will... 
    Suggested
    Home office
    Flexible hours

    Zip

    San Francisco, CA
    2 days ago
  •  ...Find out more about our hiring culture: Dream Team Culture Job Description At ZetaChain, we are seeking a dedicated Protocol Security Engineer to play a pivotal role in fortifying the security of our cutting-edge protocol. You will be deeply involved in the development... 
    Suggested
    Contract work
    Remote work
    Home office

    Blockchain Works

    San Francisco, CA
    4 days ago
  • $165k - $225k

     ...Senior Application Security Engineer Denver, CO or Long Beach, CA or SF Bay Area, CA Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. True Anomaly delivers decisive capabilities for space... 
    Suggested
    Shift work

    True Anomaly

    San Francisco, CA
    13 hours ago
  •  ...A leading software company in San Francisco is looking for an Application Security Engineer. This hybrid role requires strong experience in automated vulnerability scanning and penetration testing. Responsibilities include developing secure coding practices, conducting... 
    Suggested

    Ironclad Inc

    San Francisco, CA
    3 days ago
  •  ...and catch regressions — turning production data into better AI with every release. About the role We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted... 
    Suggested
    Flexible hours

    Braintrust Data, Inc.

    San Francisco, CA
    3 days ago
  • $325k - $405k

     ...A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience... 
    Remote work

    OpenAI

    San Francisco, CA
    4 days ago
  • $55 - $60 per hour

     ...Advanced), Node.js(Intermediate), ReactJS(Intermediate), Security Analysis(Advanced), REST API(Advanced). Contract Type: W2...  ...per hour on W2. Job Summary We are seeking an experienced Application Security Engineer IV to join our team, focusing on the design, development,... 
    Hourly pay
    Contract work

    Akraya

    San Francisco, CA
    3 days ago
  •  ...Retool Inc. in San Francisco is seeking an Application Security Engineer to enhance our security posture by identifying and addressing systemic security gaps in our codebase. This role is crucial as you will work closely with engineering teams to ensure secure practices... 

    Retool

    San Francisco, CA
    3 days ago
  • $170k - $190k

     ...collaboration and connection. There may be additional in-office days for team or company events. Ironclad is seeking a skilled Application Security Engineer with a passion for securing modern software platforms and protecting sensitive data. We are looking for someone with... 
    Full time
    Contract work
    Work at office

    Ironclad Inc

    San Francisco, CA
    2 days ago
  • $237.8k

     ...their data and AI are fully understood, secured, and resilient to enable the acceleration...  ...We are looking for a Senior Security Engineer who thinks like a product architect and...  ...processing. By submitting your application, you confirm that the information provided... 
    Base plus commission
    Local area
    Worldwide
    Shift work

    Veeam Software

    San Francisco, CA
    13 hours ago
  •  ..., PhDs, creatives, technologists, and engineers working together to empower people and...  ...The Role Want to work on building out security from the ground up at the leading edge...  ...experienced and highly motivated Senior or Staff Application Security Engineer to join our team as... 
    Hourly pay
    Full time
    Flexible hours

    Abridge

    San Francisco, CA
    3 days ago
  •  ...Ivo Inc. in San Francisco is seeking a Lead Application Security Engineer to own the security of its platform, ensuring the protection of sensitive contracts for enterprise clients. This hands-on role involves vulnerability testing, threat modeling, and mentoring engineering... 
    Work at office

    IVO Inc

    San Francisco, CA
    3 days ago
  • About Opal Security: At Opal, we’re building modern identity governance for the AI era—...  ...down innovation. The Role: Most security engineers spend their careers bolting locks onto...  ...This is not that job. We're hiring an Application Security Engineer to own security... 

    Opal Security

    San Francisco, CA
    4 days ago
  • Opal Security is looking for an Application Security Engineer to take charge of security across its product and platform. You will work closely with engineers to integrate security into the design and development process, ensuring that the systems are robust and secure... 

    Opal Security

    San Francisco, CA
    4 days ago
  • $231.9k - $318.25k

     ...directly with business data, and meets the highest standards of security and governance. AI is redefining what it means to build...  ...program have grown with it. We’re looking for an Application Security Engineer who combines deep security fundamentals with real engineering... 
    Shift work

    Retool, Inc.

    San Francisco, CA
    2 days ago
  • We are seeking a Sr. Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program. The ideal candidate will be responsible for ensuring the security of our applications throughout... 
    Remote job
    Contract work
    Flexible hours

    Zetachain

    San Francisco, CA
    4 days ago
  • $170k - $190k

    A leading software security company is hiring an Application Security Engineer in San Francisco. This hybrid role involves conducting security assessments, implementing best practices, and addressing vulnerabilities in the software. Candidates should have a BA/BS in Computer... 

    Ironclad

    San Francisco, CA
    2 days ago
  •  ...within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience. Experience with any...  ...code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT... 

    Bridge Technologies and Solutions

    San Francisco, CA
    3 days ago
  • $200k - $245k

     ...founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence...  ...and innovative problem-solving. We are seeking a Senior Application Security Engineer to lead the technical execution of our product security... 
    Full time
    Work at office
    Worldwide

    blockchaincapital.com

    San Francisco, CA
    4 days ago
  • A leading procurement technology firm in San Francisco is seeking its first Application Security Engineer to build security guardrails and enhance product security across their platforms. The successful candidate will lead security initiatives, collaborate on product launches... 

    ZipHQ, Inc.

    San Francisco, CA
    13 hours ago
  • Braintrust, based in San Francisco, is seeking an Application Security Engineer to ensure security in their high-availability data platform. This role involves reviewing code, leading security initiatives related to AI models, and managing vulnerabilities. The ideal candidate... 
    Flexible hours

    Braintrust

    San Francisco, CA
    3 days ago
  • $230k - $255k

     ...Full time Location Type Hybrid Department Security About Us: Notion helps you build...  ...path forward to the future. The Notion application is flexible, powerful and always evolving...  ...customers. Notion is looking for security engineers that have a passion for making it as... 
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Monograph

    San Francisco, CA
    1 day ago
  •  ...including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering...  ..., NVIDIA, and Databricks About the Role As our Security Engineer, Application & AI, you will own the security of our products... 
    Contract work

    Brainco

    San Francisco, CA
    4 days ago
  • $160k - $220k

     ...leading procurement platform company in San Francisco is looking for an Application Security Engineer to join their team. This role involves designing and implementing security measures, mentoring staff, and ensuring the security of the company's products. The ideal... 
    Flexible hours

    Zip

    San Francisco, CA
    1 day ago
  • A mission-driven software company in San Francisco seeks a Principal Security Engineer to enhance security measures in their applications. The role includes conducting assessments, responding to incidents, and improving security architecture while maintaining a collaborative... 

    Binti

    San Francisco, CA
    1 day ago
  • $160k - $215k

    We are seeking a highly skilled and experienced individual to join our Security & Privacy team at SPAN as a Staff Application Security Engineer. Responsibilities Lead and execute application security assessments, including static application security testing (SAST),... 
    Work at office
    Flexible hours

    I did my part and supported the Regular Toilet

    San Francisco, CA
    2 days ago
  • Abridge AI Inc. is seeking a Staff Application Security Engineer to join their team. In this role, you will drive initiatives that shape product security and mentor teams to integrate security across the organization. With 10+ years of experience, the ideal candidate will... 

    Abridge AI Inc.

    San Francisco, CA
    2 days ago
  • $225k - $400k

     ...Pinterest, Canva, and CDW. We grew 6x in 2025 and are continuing to scale fast. The Role We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed... 
    Contract work
    Work at office
    Visa sponsorship
    Relocation package

    Ivo Inc.

    San Francisco, CA
    2 days ago
  •  ...BitGo is searching for a Senior Application Security Engineer in San Francisco to lead the security strategy for high-growth digital asset platforms. This full-time onsite role involves collaborating with cross-functional teams to integrate security controls into the software... 
    Full time

    Blockchain Capital

    San Francisco, CA
    3 days ago
  • A leading AI development company in New York seeks an experienced Application Security Engineer. You will own the application security domain, embedding security in the development lifecycle, integrating tools into CI/CD, and managing vulnerabilities. The ideal candidate... 

    Mercor

    San Francisco, CA
    13 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff/Principal Application Security Engineer. Be the first to apply!