Senior / Staff Application Security Engineer
SunoGenerative AI company
Boston, United States$230,000 to $330,000Lead
Menlo Ventures
NVentures
Lightspeed Venture Partners
Hallwood Media
Matrix
Nat Friedman
Software Engineering
About the role
TL;DR
Owns product security by design, threat modeling, and building AppSec practices.
- •We’re looking for a Senior / Staff Application Security Engineer to own the security of how our product is built.
- •You’ll be the person who makes sure our code, APIs, and services are secure by design
- •threat-modeling the product, hardening the application layer, and building the AppSec practice from the ground up.
- •Key Responsibilities Execute application security end to end: threat-model features and services, and drive remediation of the most significant risks.
- •Secure the application layer against the vulnerabilities that matter most
- •injection, broken authentication and authorization, and insecure APIs.
- •Build and run a secure SDLC: code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.
- •Requirements 6+ years in security engineering with deep, hands-on application-security expertise.
- •Strong command of the vulnerability classes that cause incidents and how to eliminate them at the source
- •code, API, and authz design.
- •A builder who has stood up AppSec practices and secure-SDLC tooling, not only operated established ones.
Required skills
OWASPVaultIAMSSOMFAOAuthJWTSAMLCI/CDDockerKubernetesAWS
Nice-to-have skills
Penetration TestingSOC 2GDPRHIPAA
Domain expertise
entertainment-musicai
Benefits & perks
Company Equity Package, 401(k) with 3% Employer Match & Roth 401(k), Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options), 11 Paid Holidays + Unlimited PTO & Sick Time, 16 Weeks of Paid Parental Leave, Creative Education Stipend, Generous Commuter Allowance, In-Office Lunch (5 days per week)
Tech stack
PythonAWSGitLinuxDockerKubernetesCI/CDOAuthJWTSAMLOWASPVaultIAMSSOMFA