Jobs and Careers
BR

Staff Application Security Engineer

Braze
San Francisco, United Statesfull_timeVerifiedPosted 4 Feb 2026
💰 $245,000/yr($189,000/yr$245,000/yr)

About the role

At Braze, we have found our people. We’re a genuinely approachable, exceptionally kind, and intensely passionate crew.

We seek to ignite that passion by setting high standards, championing teamwork, and creating work-life harmony as we collectively navigate rapid growth on a global scale while striving for greater equity and opportunity – inside and outside our organization.

To flourish here, you must be prepared to set a high bar for yourself and those around you. There is always a way to contribute: Acting with autonomy, having accountability and being open to new perspectives are essential to our continued success.

Our deep curiosity to learn and our eagerness to share diverse passions with others gives us balance and injects a one-of-a-kind vibrancy into our culture.

If you are driven to solve exhilarating challenges and have a bias toward action in the face of change, you will be empowered to make a real impact here, with a sharp and passionate team at your back. If Braze sounds like a place where you can thrive, we can’t wait to meet you.

WHAT YOU'LL DO

Braze is seeking a Staff Application Security engineer to join our team. Braze is a modern, cloud-first, SaaS application company with no classical “legacy” systems. We are seeking a Staff Application Security engineer to work with our existing Application Security team to better protect our production applications and their related application infrastructure, as well as provide expert level guidance to development teams around secure architecture for their systems.

You are a person who is comfortable with, and excels in an environment where you are the sole point of technical escalation for complex, large scale software security projects. You are able to effectively, accurately, and holistically identify security issues in application architecture, in code, and in application running states.

You are an expert at communicating security requirements to developers, technical teams, and non-technical parties. You have developed your tone of delivery for all categories of recipients and have a track record of ensuring mutual understanding for your security implementation requests and assessment of risk. You have a deep understanding of SaaS software development lifecycles. You have strong, pre-formed opinions on how to ensure security in the development cycle while simultaneously creating a condition where technical teams are not burdened by controls. You have experience in both successes and failures in implementation of security controls in both the development cycle and post-production environments, and can articulate implementation importance and reasoning to both high-level engineers, academics, and management.

You are able to handle complex security incidents and escalations as a technical incident commander, and make determinations quickly, accurately, and with a cool head. You have experience with medium to large scale incident response and can process several simultaneous technical and administrative inputs while consistently working towards clear goals for remediation and containment. You are familiar with not only garden variety attack patterns, but have studied and understand TTP’s of advanced threat actors and can visually pattern match data points in order to make accurate predictions about unknowns during incidents.

WHO YOU ARE

An good candidate will have:

  • 10+ years of experience securing an application at a company at an IC level or higher
  • Demonstrable experience in consistently locating novel security vulnerabilities in web software
  • 5+ years experience conducting penetration tests both as a single tester and on a team
  • 5+ years of experience in application incident response
  • Experience with active testing against AI/LLM integrated web applications and APIs
  • Experience with scripting languages and automation
  • Direct experience in the triage/validation of vulnerabilities in systems they may not be familiar with, and the ability to properly articulate risk and provide accurate mitigation recommendations
  • Ability to read and understand Javascript, Ruby, and Kotlin (Development level proficiency not required)
  • 5+ years of experience as an Application Security leader or sole responsible party

An excellent candidate will have:

  • Experience with Mail Delivery systems/experience in the MarTech space
  • Experience managing a public bug bounty program
  • CVE’s or published vulnerabilities, and corresponding conference talks
  • Involvement with an open source project
  • Experience with the review and risk evaluations of 3rd party integrations
  • Experience with mobile application penetration testing (including testing methodologies that include location of security vulnerabilities in applications with pinned

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Braze

View company profile →