Skip to main content
SentinelOne

Staff AppSec Engineer

RemoteUnited States only
Published
Role
Security
Experience
Staff
$156k–$190k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Staff application security (AppSec) engineer with 7+ years in application/product security and a strong software development background. Expert in SAST and deep code review, requiring expert-level knowledge of at least two of C, C++, Rust, and Java. This is a U.S.

Core skills

C/C++/Rust/Java

Required skills

SASTSAMLOAuthOIDCJWTGitCI/CD

Optional skills

PythonDjangoFlaskNode.jsExpressIDA ProBinary NinjaGhidra

What you'll do

  • Lead Wayfinder Frontier AI Services customer engagements end-to-end, scope work, deliver technical findings, and present results to executive and technical stakeholders.
  • Review and triage findings from the agentic code scanning pipeline against customer C, C++, Rust, and Java codebases; validate true positives and eliminate noise.
  • Conduct deep code review across C, C++, Rust, and Java and common frameworks; translate technical risk into business impact and map exposures into exploitation chains.
  • Author and maintain SAST rule packs and partner with AI/ML engineers to improve the agentic scanning engine; work with engineering to reduce false positives.
  • Provide remediation guidance to customer development teams, validate fixes through follow-up review, mentor senior AppSec engineers, and define/refine engagement playbooks and scoping templates.

What they require

  • 7+ years in application security or product security with a strong software development background.
  • Expert-level knowledge of at least two of: C, C++, Rust, Java.
  • Mastery of OWASP Top 10 and CWE Top 25; familiarity with modern authentication infrastructure (SAML, OAuth, OIDC, JWT internals); experience driving an application through ASVS Level 4 verification.
  • Hands-on experience authoring custom static-analysis rules and queries for modern SAST engines and validating findings from automated/agentic analysis pipelines; strong threat modeling experience through the secure SDLC.
  • Fluency with Git-based source control and CI/CD pipelines, including build-pipeline security controls, runner hardening, and release-gate enforcement. Preferred: OSWE, CSSLP, GWAPT, published CVEs, or conference talks.

Benefits

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • 401(k) retirement plan with company match
  • Medical, dental, and vision coverage

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Its AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response.

CybersecurityEnterprisesentinelone.com/

What people say about this company

3.3/ 5

  • Employees appreciate the innovative technology and products offered by SentinelOne.
  • The company has a collaborative work culture that fosters teamwork.
  • Some employees report issues with management and communication.
$156k–$190k/yr