Staff/Principal Application Security Engineer
Binti Inc
Binti builds software for state and county government agencies, focusing on reinventing social services. We started in child welfare, with the mission of helping every child have a safe, loving, and stable family. To date, we've helped approve more than 100,000 families to foster or adopt, and we support over 49% of the nation's child welfare system. We have expanded our product offerings in child welfare, moving more to the root of the problem, helping families stay together and avoid separation, and are now expanding horizontally across other areas in social services.
Binti is a for-profit, mission-driven software company based in San Francisco, CA. Investors include Founders Fund, First Round Capital, Kapor Capital, and others. We're a team of ~90 people and growing quickly. We care about creating a workplace where everyone feels welcome and can bring their full self to work. We have a huge, ambitious vision to rewire government to be more effective in expanding opportunities for people around the world, and we are looking for mission-driven, high-empathy, high-performance, and low-ego team members to join us on our exciting journey towards that vision. As Binti's first Principal Security Engineer (Applications focused), reporting to our CTO, you will play a critical role in ensuring the security and integrity of our software applications. You will work alongside Binti's full-stack engineers, contribute to security controls in our software, identify and address potential security vulnerabilities, implement best practices, and uphold secure coding standards. WHAT YOU WILL DO- Conduct Security Assessments: Provide holistic assessments of Binti's security stance, including performing regular security reviews, code audits, penetration testing, and threat modeling to maintain the highest standard of application security.
- Set Direction: Help Binti chart a specific and pragmatic course of action to achieve a strong security posture. This includes scoping and prioritizing work, determining what levels of investment and risk we should take on given our scale and capacity, contributing to job descriptions and hiring plans for the next team members, and building relationships across teams and with company leadership to effectively communicate and advocate for these goals.
- Respond To Incidents: Respond promptly to security incidents, collaborate with engineers on-call, and provide detailed post-event analyses. Evaluate the applicability of emergent security concerns through risk rating and assessment (such as OWASP).
- Improve Security Architecture: In a leadership capacity with the Engineering team, identify, design, and implement technologies to enhance security automation, during the software development lifecycle, within the product itself, and in cloud hosting environments.
- Set Security Standards: Lead efforts to design and implement secure coding standards and best practices across the development lifecycle, with an eye toward automation, including effective AI tools
- Share Expertise: Stay up to date on the latest security threats, vulnerabilities, and industry best practices, and ensure the integration of this knowledge into Binti's security strategies. Act as our company's expert on application security matters, providing mentorship to development teams and fostering a scalable, security-aware culture.
- Represent the Security team to other Binti teams and Binti leadership: Act as a steward of the Binti values. Tell the story of the security team, advertising its good work, and celebrating wins.
- Review and implement security patches and hotfixes in production applications.
- Implement streamlined feedback of security recommendations for new products before launch into the Binti platform.
- Improve the security of documents and files uploaded and downloaded on the platform.
- Analysis, scoping, and implementation of security improvements to better protect Personal Health Information and Personally Identifiable Information stored within the product.
- Improve notification and escalation of security concerns from third parties (such as security researchers).
- Integration of new and existing logging and alerting systems to centralized and/or decentralized Security Incident and Event Management (SIEM) platforms.
- Assess backlog of application-specific security tickets and provide recommendations for remediation and
- Support evidence collection for compliance frameworks such as SOC 2 Type II and HIPAA.
- In partnership with a vendor, stand up a bug bounty program and drive engagement from external security researchers
- Drive the timely completion of critical security tasks (e.g. incident remediation follow-ups), sometimes implementing personally, and sometimes overseeing the implementation by full-stack engineers.
- Technical Expertise: Proven experience as an Application Security Engineer or in a similar role. Strong technical background with experience in full-stack development, cloud computing, and scalable architecture. Proficiency in one or more OOP coding languages (Ruby, Python, Java, etc) is strongly preferred.
- Deep Understanding: Strong understanding and knowledge of web application security principles, common vulnerabilities, and best practices.
- Collaborative Approach: Excellent communication skills with the ability to simply convey complex security concepts to non-technical stakeholders and clearly articulate the relative risks and trade-offs.
- Product Orientation: Focused on keeping the company secure while ensuring the team can still ship products and deliver value to customers and users.
- Decisions That Scale: Experience cultivating a security-aware development culture that scales through mentorship and automation.
- Passion for Social Impact: A genuine interest in leveraging technology to address social challenges, with a strong sense of purpose in improving outcomes for children in need.
- Drive urgency with intention: A sense of pragmatism, resourcefulness, and focus to advance our security goals with a relatively small team.
- Big plus - prior experience with GovTech or FedRamp
- An above-market compensation package (salary + equity)
- Excellent medical, dental, vision, and life insurance - 99% of insurance premiums covered for you + your dependents
- Flexible vacation time to promote a healthy work-life blend
- 13 paid holidays; 11 federally observed holidays (including Juneteenth), plus Election Day and the day after Thanksgiving
- 16 weeks of paid parental bonding leave for the arrival of a newborn or newly placed infant
- Sick/mental health time separate from vacation days (accrue up to a cap of 80 hours)
- 4 weeks of sabbatical after 4 years of service at the company
- 401k, Commuter benefits, FSA, and DCFSA with administration paid for
- $5,000 annual bonus for employees who volunteer as a CASA (court-appointed special advocates)
- $2,500 annual reimbursement for ongoing learning and development, with opportunities to attend trainings/conferences, on-site speaker series, and lunch and learns
- $300 reimbursement for initial office setup
- $50 a month effective work reimbursement to cover internet, electricity, office setup costs, or lunch/snacks with coworkers
- Paid jury duty
At Binti, we celebrate having a diverse team and believe our differences make us stronger. Binti is proud to be an equal-opportunity workplace and is an equal-opportunity employer. We welcome all qualified applicants to apply without regard to race, color, religion, gender, sexual orientation, age, national origin, disability, or protected Veteran status.
$200k - $340k
...Application Security Engineer Palo Alto, CA About XAI XAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This...SuggestedTemporary work$27 per hour
...We are seeking a Sr. Application Security or DevSecOps Engineer with broad set of experiences to have an early and formative impact in many areas of the ZetaChain security program. The ideal candidate will be responsible for ensuring the security of our applications throughout...SuggestedContract workRemote workFlexible hours- ...UK, Europe, Japan and Canada, and has been used for more than 500,000 patients worldwide. We are looking for an Application Security Engineer to work with our engineering team to ensure security is an integral part of our Software Development Lifecycle (SDLC)....SuggestedWork at officeLocal areaWorldwideRelocation3 days per week
- ...About Opal Security: At Opal, we're building modern identity governance for the AI... ...innovation. The Role: Most security engineers spend their careers bolting locks onto... ...is not that job. We're hiring an Application Security Engineer to own security...Suggested
$180k - $220k
...Senior Application Security Engineer, AI and Machine Learning San Francisco, California, United States; Seattle, Washington, United States Who We Are Lightning AI is the company behind PyTorch Lightning. Founded in 2019, we build an end-to-end platform for developing...SuggestedWork at officeWork from homeFlexible hours2 days per week$160k - $240k
..., and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before... ...and integrity of our customers' data. As our first Application Security Engineer , you will take on a dynamic and high impact role. You will...Home officeFlexible hours$213k
...Senior Application Security Engineer Remote, USA; San Francisco, CA, USA About the Role We are looking for a Sr. Full Stack Application Security Engineer with deep expertise in mobile application security to join our Product Security team. This role is hands-on...Full timeWork at officeLocal areaRemote workNight shift- ...Senior Security Engineer – Secure Code Review San Francisco, California On-site | Full-Time My client is seeking a Senior Security Engineer to join their Application Security practice. This role is ideal for a hands-on AppSec professional with a strong software...Full time
- ...Application Security Engineer The Application Security Engineer will be responsible for analyzing software code repositories, code designs, processes... ...interpersonal skills, with the ability to enable fellow staff through training, communication and mentorship Problem...
$192k - $240k
...Engineering at Brex Engineering at Brex is about building systems that scale with speed and... .... Our teams span Software, Data, Security, and IT, and operate with high autonomy... ...become leaders. What you’ll do As a Senior Application Security Engineer, you will focus on finding...Work experience placement$185k - $260k
...Application Security Engineer Mountain View, CA About Glean: Glean is the Work AI platform that helps everyone work smarter with AI. What began as the industry's most advanced enterprise search has evolved into a full-scale Work AI ecosystem, powering intelligent Search...Work at officeFlexible hours- ...Senior Application Security Engineer Imprint is reimagining co-branded credit cards & financial products to be smarter, more rewarding, and truly brand-first. We partner with companies like Crate & Barrel, Rakuten, Booking.com, H-E-B, Fetch, and Brooks Brothers to launch...Remote workFlexible hoursShift work3 days per week
$230k - $280k
...day. Our users depend on us to deliver a secure and trustworthy experience, and we value... ...path forward to the future. The Notion application is flexible, powerful and always evolving... .... Notion is looking for security engineers that have a passion for securing complex...Full timeLocal areaRemote workFlexible hours$146k - $175k
...Senior Application Security Engineer, Ai & Product Security Artera is seeking a hands-on Senior Application Security Engineer, AI & Product Security to work alongside our AI builders and Systems Engineers to threat-model agentic and LLM-powered features, harden PHI/...Temporary workSummer workSummer holidayCurrently hiringWork at officeLocal areaImmediate startRemote workFlexible hoursShift work3 days per week$170k - $190k
...collaboration and connection. There may be additional in-office days for team or company events. Ironclad is seeking a skilled Application Security Engineer with a passion for securing modern software platforms and protecting sensitive data. We are looking for someone with...Full timeContract workWork at office$225k - $400k
...Canva, and CDW. We grew 6x in 2025 and are continuing to scale fast. The Role We're hiring our first dedicated Lead Application Security Engineer to own the security of the Ivo platform end to end. You'll partner directly with our Head of IT & Security and embed...Contract workWork at officeVisa sponsorshipRelocation package$170k - $190k
A leading software security company is hiring an Application Security Engineer in San Francisco. This hybrid role involves conducting security assessments, implementing best practices, and addressing vulnerabilities in the software. Candidates should have a BA/BS in Computer...- A leading software company in San Francisco is looking for an Application Security Engineer. This hybrid role requires strong experience in automated vulnerability scanning and penetration testing. Responsibilities include developing secure coding practices, conducting...
$231.9k - $318.25k
...directly with business data, and meets the highest standards of security and governance. AI is redefining what it means to build... ...program have grown with it. We’re looking for an Application Security Engineer who combines deep security fundamentals with real engineering...Shift work$272k - $320k
...organization in California is looking for a Security Architect to tackle complex security... ...5 years of experience in web, mobile, application, or blockchain security. You'll perform... ...solutions, working closely with engineering teams. The salary for this position ranges...- ...and catch regressions — turning production data into better AI with every release. About the role We're looking for an Application Security Engineer who lives in the code. Braintrust is a real-time, high-availability data platform that runs in both SaaS and self-hosted...Flexible hours
- A leading procurement technology firm in San Francisco is seeking its first Application Security Engineer to build security guardrails and enhance product security across their platforms. The successful candidate will lead security initiatives, collaborate on product launches...
- ...within a Vulnerability Management Program that understands Application Security with 5-7 years of security experience. Experience with any... ...code review experience using automated toolsets Software Engineering career experience Following Certifications: CISSP, CEH, GWAPT...
- ...including Patrick Collison and Andrej Karpathy. We are building AI applications for the world's most important institutions, delivering... ..., NVIDIA, and Databricks About the Role As our Security Engineer, Application & AI, you will own the security of our products...Contract work
$325k - $405k
A leading AI research firm in San Francisco is seeking a Security Engineer for Application Security. The role involves identifying and mitigating security vulnerabilities, conducting assessments, and developing security tools. Ideal candidates will have extensive experience...Remote job$230k - $255k
...Full time Location Type Hybrid Department Security About Us: Notion helps you build... ...path forward to the future. The Notion application is flexible, powerful and always evolving... ...customers. Notion is looking for security engineers that have a passion for making it as...Full timeWork at officeLocal areaRemote workFlexible hours- Braintrust, based in San Francisco, is seeking an Application Security Engineer to ensure security in their high-availability data platform. This role involves reviewing code, leading security initiatives related to AI models, and managing vulnerabilities. The ideal candidate...Flexible hours
$160k - $220k
...leading procurement platform company in San Francisco is looking for an Application Security Engineer to join their team. This role involves designing and implementing security measures, mentoring staff, and ensuring the security of the company's products. The ideal...Flexible hours- A mission-driven software company in San Francisco seeks a Principal Security Engineer to enhance security measures in their applications. The role includes conducting assessments, responding to incidents, and improving security architecture while maintaining a collaborative...
- Ivo Inc. in San Francisco is seeking a Lead Application Security Engineer to own the security of its platform, ensuring the protection of sensitive contracts for enterprise clients. This hands-on role involves vulnerability testing, threat modeling, and mentoring engineering...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff/Principal Application Security Engineer. Be the first to apply!
- assistant principal San Francisco, CA
- staff security engineer San Francisco, CA
- assistant engineer San Francisco, CA
- engineering aide San Francisco, CA
- assistant chief engineer San Francisco, CA
- staff engineer San Francisco, CA
- technology administrator San Francisco, CA
- senior staff systems engineer San Francisco, CA
- assistant mechanical engineer San Francisco, CA
- staff data engineer San Francisco, CA

