CybersecurityJobs.io
← Back to all jobs

Job Description

Lead Application Security Engineer role focused on strengthening application security capabilities through engineering partnership and scalable security automation.

Responsibilities

  • Partner with the Director of Information Security and software engineering teams to advance Panthalassa’s AppSec program
  • Assist the Head of Information Security with building out the AppSec function
  • Perform code reviews and service architecture reviews to provide security guidance
  • Lead engineers in threat modeling for applications and services
  • Collaborate to define security metrics that are culturally useful for engineering teams
  • Support security hiring by assisting with interviews and onboarding for additional Security personnel
  • Assist with incident response during current growth phases and provide escalation support as the team scales
  • Integrate, maintain, and automate security scanning in CI/CD pipelines, including:
    • SAST
    • DAST
    • SCA
    • secrets management
  • Build and integrate agentic security tools to meet Panthalassa security needs
  • Conduct hands-on threat modeling and architectural design reviews for new features and applications before code is written
  • Perform manual and automated secure code reviews and targeted penetration testing for web and mobile applications
  • Help manage external Vulnerability Disclosure or Bug Bounty programs
  • Translate regulatory compliance requirements into practical engineering tasks

Requirements

  • 6+ years of experience with application security processes
  • 2+ years experience as a Team Lead or Manager of an Application Security team
  • Broad and deep application security foundational knowledge
  • Professional experience using AI systems and agents for security outcomes
  • Deep understanding of OWASP Top 10 and CWE Top 25, plus secure design patterns
  • Hands-on experience with industry-standard tools, including:
    • Snyk
    • GitHub Advanced Security
    • Burp Suite
    • Fortify
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience

Technologies

  • SAST, DAST, SCA, secrets management
  • CI/CD pipelines
  • AI systems, agentic security tools
  • OWASP Top 10, CWE Top 25
  • Snyk, GitHub Advanced Security, Burp Suite, Fortify
  • Web and mobile applications

Desired Qualifications

  • Experience with software development work related to mechanical engineering environments
  • Familiarity with cloud platforms (AWS, Azure, or GCP)
  • Experience with Docker, Kubernetes, and Infrastructure as Code (IaC)

Benefits

  • Cash compensation: $200,000 - $260,000 per year
  • Equity in the company
  • Flexible paid time off
  • Health insurance: company pays 100% of gold-level PPO plan for full-time employees, partners, and dependents
  • Dental insurance: company pays 100% for full-time employees, partners, and dependents
  • Vision insurance: company pays 100% for full-time employees, partners, and dependents
  • Disability insurance: company pays 100% for long-term financial support if you become disabled
  • Ability to contribute to tax-advantaged accounts including 401(k), health FSA, and dependent care FSA
  • Relocation assistance to facilitate moving to Portland (if needed)

Additional Requirements

  • Travel to conferences, vendors, and test sites as needed
  • Intermittently able to work longer hours and weekends to support critical needs

Location: Portland, OR (on-site). Offices, lab, and shop located in Portland, Oregon.

Similar Jobs