Jobs and Careers
SP

Senior Application Security Engineer

Sprout Social
Remote US, United StatesRemotefull_timeVerifiedPosted 9 Jun 2025
💰 $241,164/yr($146,200/yr$241,164/yr)

About the role

Description

Sprout Social is looking to hire a Senior Application Security Engineer to the Security team.

 

Why join Sprout’s Security team?

Security sits at the intersection of empowering teams to move quickly and mitigating risks to our overall business. We are enablers who strive to hone our unique craft and minimize friction or red tape. Our security team ensures that we are designing platforms, implementing tools and building products with security in mind. This team owns the security posture of our entire organization, including our development, production environments, and internal concerns. As a part of this team, you are given the space and encouraged to stretch beyond your core function and make a deeper impact on the broader organization.  In short, the work you do here matters, and you feel that day in and day out. 

 

What you’ll do

  • Implement SAST, DAST and SCA tooling as part of security hygiene and integrated into CI/CD pipelines
  • Ensure that we are designing platforms, implementing tools and building products with security in mind. 
  • Serve as trusted advisor and collaborator to developers to identify new threats, attack methods, and techniques, to develop and prioritize mitigation plans (threat modeling & governance)
  • Influence stakeholders to correct security deficiencies in solution design as well as developed code
  • Collaborate with partners in infrastructure and engineering to measurably harden, monitor, and ensure resilience for our cloud-hosted platforms and software development lifecycle.
  • Establish, manage, and own risk based cross-organizational projects and work to continuously improve our security posture
  • Integrate with a maturing vulnerability management program to ensure tracking and remediation of security issues.

 

What you’ll bring

We’re looking for an engineer with passion for working collaboratively with developers and a desire to ensure that software applications are built with the highest level of security. If you're ready to join a dynamic team of developers and security experts, and help create software that is secure from the ground up, we’d love to talk with you!

 

Qualifications

The minimum qualifications for this role include:

  • 3+ years of programming and/or DevOps experience and 3+ years of information security experience
  • Experience performing security testing of an application using Static Application Security testing (SAST), Dynamic Application Security Testing (DAST) and Open Source Analysis (SCA) tooling.  
  • Experience in reviewing findings from the above tools to analyze false positives and recommend security fixes.
  • Demonstrated comprehension of the OWASP Top 10 and an ability to communicate with developers and application architects.

 

Preferred qualifications for this role include:

  • Information security qualification such as CISSP
  • GIAC or related certifications related to application pen testing or secure development 
  • Experience with threat modeling and familiar with using frameworks to guide decision making based on risk tolerance and business objectives
  • Experience with technology/tools such as Kubernetes, Docker, Jenkins, Terraform, AWS, Github, etc
  • Experience automating security testing into CI/CD pipelines

 

How you’ll grow

Within 1 month, you’ll plant your roots, including:

  • Experiencing Sprout’s in-depth onboarding, covering everything from our company mission and values, hearing directly from executives and founders, to deep training on our products and the value that Sprout delivers to our customers
  • Making a plan with your manager to set initial priorities, align on expectations for your role, plant goalposts for your career, and learn about Sprout’s approach to security
  • Meeting Sprout’s security stakeholders across the organization
  • Learning our existing tooling and begin monitoring the status of our environments
  • Collaborating regularly with teammates and  members of our infrastructure and development teams and get up to speed on our current and future initiatives
  • Getting regular feedback on your approach to managing and engaging our existing risks and security capabilities

Within 3 months, you’ll start hitting your stride by:

  • Working with your manager and teammates to create and prioritize quarterly team goals
  • Deconstructing larger security projects into smaller, more manageable deliverables
  • Starting to understand the breadth and depth of technologies and tools under the team’s purview
  • Reviewing, refining and triaging alerts triggered from our

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sprout Social

View company profile →