Skip to main content
Censys

Staff Application Security Engineer

RemoteUnited States, Canada only
Published
Role
Security
Experience
Lead
Employment
Full-time
$198k–$233k/yr
Check eligibility

Open to US, CA only. Set where you work from to check your eligibility.

No BS summary

Staff Application Security Engineer needed with 10+ years of experience in Security Engineering, DevSecOps, or SRE. Must have deep expertise in securing Kubernetes and strong experience with AppSec tooling integrated into CI/CD pipelines. Cloud services (GCP preferred) and Infrastructure-as-Code proficiency are required. Role involves owning the application security strategy, designing secure paths, and setting technical direction across the software lifecycle.

Core skills

KubernetesApplication SecurityDevSecOps

Required skills

GCPCI/CDcode scanningsecret detectionsoftware composition analysisinfrastructure policy enforcementInfrastructure-as-CodeTerraformCrossplanePythonBash

Optional skills

Orca SecurityAikido SecurityTensorFlowPyTorchWeb Application Firewalls (WAF)anti-DDoS systemsedge protection technologiesPrometheus

Required languages

English

What you'll do

  • Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates
  • Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads
  • Lead the integration of security into CI/CD pipelines — code scanning, secret detection, software composition analysis, and infrastructure policy enforcement — partnering with engineering teams to adopt them without friction
  • Deliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organization
  • Set the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance tracking
  • Partner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracy
  • Provide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teams
  • Participate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readiness

What they require

  • 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teams
  • Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane)
  • Strong experience with Application Security tooling — dependency scanning, static analysis, and policy enforcement — integrated into CI/CD pipelines such as GitHub Actions and ArgoCD, and the ability to bridge engineering practices with Security Operations
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs), and familiarity with frameworks like MITRE ATT&CK
  • Strong grasp of cloud services (GCP preferred), especially securing data pipelines, model hosting endpoints, and related infrastructure
  • Proficiency with Infrastructure-as-Code (Terraform, Crossplane, or similar) and security scanning for cloud resources
  • Proficiency with scripting and automation (e.g., Python, Bash)
  • The ability to thoughtfully participate in technical discussions and drive towards data-driven decisions amidst ambiguity and competing priorities
  • Strong communication skills and empathy for developer needs, with a demonstrated ability to embed secure practices without creating friction
  • Experience building or scaling an AppSec or DevSecOps program from early maturity, including establishing paved roads and measuring adoption
  • Familiarity with commercial security platforms such as Orca Security (CNAPP/cloud security posture) and Aikido Security (application security scanning) is a plus
  • Experience securing ML toolchains (e.g., TensorFlow, PyTorch) and familiarity with AI-specific threats such as data leakage, model inversion, prompt injection, and adversarial inputs
  • Hands-on experience integrating and managing Web Application Firewalls (WAF), anti-DDoS systems, and edge protection technologies
  • Familiarity with monitoring and observability systems (e.g., Prometheus, Grafana, OpenTelemetry) with a focus on detecting security anomalies
  • Familiarity with AI governance and compliance standards (e.g., EU AI Act, NIST AI Risk Management Framework)
  • Strong interest in harnessing AI and LLM tools as a force multiplier — using them to code smarter, iterate faster, boosting productivity and enhancing product capabilities

Benefits

  • equity
  • health, dental & vision coverage
  • retirement with company contribution
  • parental leave
  • mental health & wellness benefits
  • flexible PTO
  • professional development stipend
  • sales incentive pay for most sales roles
  • annual bonus plan for eligible non-sales roles
  • reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment

Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide. Its platform helps security teams uncover hidden threats, gain actionable insights, and build proactive defense strategies.

🇺🇸 United StatesCybersecurityStartupcensys.io/
$198k–$233k/yr