Jobiglo

No results.

Staff Security Engineer, Application Security

fomo-labs · New York City

Senior 🇬🇧 English
SAST DAST software composition analysis secrets scanning CI/CD security gates penetration testing API security authentication authorization threat modeling vulnerability management

Job description

About the role

We are looking for a Staff Security Engineer to lead and expand our application security program. This hands‑on, high‑leverage position will serve as the technical authority for building secure software across the product lifecycle.

Key responsibilities

  • Lead security architecture reviews and threat modeling for new features and major system changes, partnering with engineering and product from design through launch.
  • Own the secure SDLC program, including static and dynamic analysis (SAST/DAST), software composition analysis, secrets scanning, and CI/CD security gates.
  • Perform deep‑dive code reviews and manual penetration testing of high‑risk services, APIs, and web applications.
  • Design and build internal security tooling and guardrails that enable engineers to move fast without introducing risk.
  • Run and mature the vulnerability management program, handling triage, severity scoring, and remediation coordination.
  • Manage relationships with external pentest vendors and bug bounty programs, turning findings into durable fixes.
  • Set technical direction on authentication, authorization, API security, and data‑protection patterns used across the product.
  • Mentor engineers on secure coding practices and act as the go‑to resource for security questions.
  • Contribute to incident response for application‑layer issues and help define the overall AppSec roadmap and metrics.

Required profile

  • 7+ years of experience in security engineering with a recent focus on application security.
  • Proven ability to lead security initiatives and influence product and engineering teams.
  • Hands‑on experience conducting threat modeling, security architecture reviews, and penetration testing.
  • Strong track record of building and operating secure SDLC processes and tooling.

Required skills

  • SAST and DAST
  • Software composition analysis
  • Secrets scanning
  • CI/CD security gates
  • Penetration testing
  • API security
  • Authentication and authorization design
  • Threat modeling
  • Vulnerability management

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec fomo-labs.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:ashby

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 week ago

Expires 1 month from now

11 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

fomo-labs

New York City