Jobs and Careers
UN

Application Security Engineer - SF - Hybrid Preferred, Remote O.K.

Unit21
San Francisco, United StatesRemotefull_timeVerifiedPosted 17 Dec 2025
💰 $175,000/yr($155,000/yr$175,000/yr)

About the role

About the role

As a Senior Application Security Engineer, you will be a hands-on builder responsible for protecting our platform, our customers, and their data. This is not a governance role; you will spend your time in the code, designing and implementing the systems that secure our products from the ground up. You will own critical security infrastructure, build automations to eliminate entire classes of vulnerabilities, and serve as a deep technical expert for our engineering organization. This role is for an engineer who is passionate about security and wants to solve complex security problems at scale through high-quality, maintainable code.

What you'll be doing:

  • Design, code, and deploy automated security controls, services, and frameworks to prevent vulnerabilities at scale.

  • Build, own, and operate the tools and infrastructure for our application security program, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and secret scanning solutions.

  • Perform hands-on threat modeling, security architecture reviews, and in-depth code reviews (Python/TypeScript) for new products and critical features to ensure they are secure by design.

  • Conduct penetration tests and vulnerability assessments against our applications and APIs to proactively identify and remediate security weaknesses.

  • Develop custom tools and automation to streamline security operations and enhance our detection and response capabilities.

  • Act as a key member of our incident response team during security events.

  • Mentor and educate product engineers on secure coding best practices, acting as a subject matter expert and fostering a culture of security ownership.

What we're looking for:

Experience:

  • 4+ years of hands-on experience in a software engineering or application security role, with a proven track record of shipping code and building security solutions.

  • Demonstrated history of successful cross-organizational efforts and the ability to drive complex technical projects to completion.

Programming & Scripting:

  • Expert-level proficiency in Python, including experience building security tools, automation scripts, or backend services.

  • Professional experience with Go or TypeScript is a significant plus.

Security Expertise:

  • Deep, hands-on knowledge of common application vulnerabilities, such as the OWASP Top 10, and their mitigation techniques.

  • Proven experience integrating, fine-tuning, and operating security tools (e.g., SAST, DAST, SCA) within developer workflows.

  • Experience conducting manual penetration tests and vulnerability assessments on web applications and APIs. <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Unit21

View company profile →