Application Security Engineer
Our mission is to be the technology backbone for strategic competition against peer adversaries. These missions – including intelligence, information operations, special activities, and perception management – are happening today and their success or failure will determine if we go to war tomorrow.
We've been on the front lines of these missions since 2019, and have grown to support a wide range of missions across all US service branches, multiple combatant commands, partner nations, and interagency stakeholders. We deploy both hardware and software products to support people on the front lines that span collection, planning / assessments, and effects.
We've grown from $3M in run-rate revenue in 2021 to $80M in run-rate revenue today. We've been profitable since 2022 and have raised $91M in venture capital funding through Series B. We're valued at $1.5B as of 2025.
About the role
As the Founding Application Security Engineer, you will own and build the security backbone of our SaaS platform, ensuring we can ship features quickly — and safely — to our customers. You will partner with software, DevOps, and platform teams, while coordinating with audit partners, to embed threat modeling, automated SAST/SCA/DAST, and rapid vulnerability response into every stage of our SDLC. Your leadership will be pivotal in protecting customer data, meeting compliance milestones, and scaling our security posture as the company grows.What you'll do- Map our product attack surface, rank risks, and publish a 12-month security roadmap.
- Embed with development teams to run threat models, review critical PRs, and coach secure-by-default habits.
- Help implement and deploy SAST, SCA, secrets-scan, DAST, and container/IaC checks in CI/CD; drive MTTR on P1 vulns to
- Coordinate with DevOps for application security issues that cross between application and infrastructure layers
- Support incident-response for product issues and feed lessons back into code, docs, and process.
- Write customer-facing Product Security white-papers and supply compliance evidence.
Qualifications
- 5 + years in Application / Product Security
- Ability to read & write production-quality code
- Hands-on experience securing web applications and automating AppSec workflows.
- Familiarity with incident response fundamentals—log triage, forensics, retros—and a passion for eliminating root causes.
- Clear, concise communicator who can translate risk for engineers, leadership, and customers.
- Ideally experienced with AWS, Python, containers, TypeScript, Node.js, Django, PostgreSQL, and Rancher.
- Experience securing LLM workflows is a big plus
Benefits:
- Health, dental, and vision insurance
- 100% remote - work from anywhere in the US
- 401k matching
- Mental benefits
- Flexible work environment - you manage your workday
- Pet and child care reimbursement during travel
- Unlimited PTO
Originally posted on Himalayas
Apply To this Job