Staff Application Security Engineer (R5949)
TECHNICAL STACK · 1 TAGS
OVERVIEW
The successful candidate combines technical application-security depth with the programmatic leadership to drive enterprise-wide improvement. You will help teams build, test, package, release, and maintain secure software while ensuring security controls are practical, measurable, and integrated into existing engineering workflows.
This is a Staff level individual-contributor role with significant influence across engineering, security, product, and technology leadership.
WHAT YOU'LL DO
* Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.
* Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.
* Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.
* Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.
* Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.
* Evaluate, implement, tune, and operationalize application-security tooling, including:* Static application security testing (SAST)
* Dynamic application security testing (DAST)
* Software composition analysis (SCA)
* Secrets detection
* Infrastructure-as-code security scanning
* Container and image security scanning
* API and cloud-native application security controls
* Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.
* Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.
* Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.
* Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.
* Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.
* Mature software supply-chain security practices, including:* Machine-readable software bills of materials (SBOMs)
* Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications
* Build and release provenance
* Artifact, package, container-image, and binary signing
* Artifact verification and trusted promotion processes
* Secure artifact repositories and package registries
* Approved dependency sources and package integrity verification
* SLSA-aligned build integrity, provenance, and release controls
* Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.
* Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
* Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.
* Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.
* Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
* Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.
NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.
REQUIRED QUALIFICATIONS
* Demonstrated experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams.
* Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.
* Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices.
* Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling.
* Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
* Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition.
* Knowledge of common application-security risks, including authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.
* Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
* Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.
* Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable secure-development and supply-chain security frameworks.
* Ability to read and assess production code and scripts in one or more modern programming languages.
* Strong written and verbal communication skills, including the ability to explain technical risk and tradeoffs to developers, leaders, auditors, and nontechnical stakeholders.
PREFERRED QUALIFICATIONS
* Experience with VEX, CSAF, SBOM formats such as SPDX or CycloneDX, and component or vulnerability intelligence workflows.
* Experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.
* Experience with common source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.
* Experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies.
* Experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements.
* Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance product environments.
* Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.
QUESTIONS AND ANSWERS
- How much does the Staff Application Security Engineer (R5949) at Shield AI pay?
- The posting lists a range of $143K–$214K per year. Ranges reflect what Shield AI publicly declared on the source posting.
- Where is this Staff Application Security Engineer (R5949) role based?
- The role is based in Remote and is open to remote candidates.
- What experience does Shield AI expect for this role?
- The posting is tagged as a lead-level role, typically 7+ years of experience. Check the requirements section for specifics.
- Where is Shield AI headquartered?
- Shield AI is headquartered in San Diego, USA.
- How was this posting sourced?
- This role was pulled directly from Shield AI's Lever careers site. Apply links open in the employer's own ATS — no reposts or aggregator middleware.
Apply links open in the employer's official ATS. Always verify recruitment messages on the company's careers page before sharing personal information.