Lead Application Security Engineer
Agentic Security
Application Security
Automated Security Testing
Ci/cd Security
Cwe
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
Owasp
Secret Management
Security
Security Automation
Security Standards
Security Testing
Software Security
Static Application Security Testing
Static Code Analysis
Job Description
Lead Application Security Engineer role focused on strengthening application security capabilities through engineering partnership and scalable security automation.
Responsibilities
- Partner with the Director of Information Security and software engineering teams to advance Panthalassa’s AppSec program
- Assist the Head of Information Security with building out the AppSec function
- Perform code reviews and service architecture reviews to provide security guidance
- Lead engineers in threat modeling for applications and services
- Collaborate to define security metrics that are culturally useful for engineering teams
- Support security hiring by assisting with interviews and onboarding for additional Security personnel
- Assist with incident response during current growth phases and provide escalation support as the team scales
- Integrate, maintain, and automate security scanning in CI/CD pipelines, including:
- SAST
- DAST
- SCA
- secrets management
- Build and integrate agentic security tools to meet Panthalassa security needs
- Conduct hands-on threat modeling and architectural design reviews for new features and applications before code is written
- Perform manual and automated secure code reviews and targeted penetration testing for web and mobile applications
- Help manage external Vulnerability Disclosure or Bug Bounty programs
- Translate regulatory compliance requirements into practical engineering tasks
Requirements
- 6+ years of experience with application security processes
- 2+ years experience as a Team Lead or Manager of an Application Security team
- Broad and deep application security foundational knowledge
- Professional experience using AI systems and agents for security outcomes
- Deep understanding of OWASP Top 10 and CWE Top 25, plus secure design patterns
- Hands-on experience with industry-standard tools, including:
- Snyk
- GitHub Advanced Security
- Burp Suite
- Fortify
- Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience
Technologies
- SAST, DAST, SCA, secrets management
- CI/CD pipelines
- AI systems, agentic security tools
- OWASP Top 10, CWE Top 25
- Snyk, GitHub Advanced Security, Burp Suite, Fortify
- Web and mobile applications
Desired Qualifications
- Experience with software development work related to mechanical engineering environments
- Familiarity with cloud platforms (AWS, Azure, or GCP)
- Experience with Docker, Kubernetes, and Infrastructure as Code (IaC)
Benefits
- Cash compensation: $200,000 - $260,000 per year
- Equity in the company
- Flexible paid time off
- Health insurance: company pays 100% of gold-level PPO plan for full-time employees, partners, and dependents
- Dental insurance: company pays 100% for full-time employees, partners, and dependents
- Vision insurance: company pays 100% for full-time employees, partners, and dependents
- Disability insurance: company pays 100% for long-term financial support if you become disabled
- Ability to contribute to tax-advantaged accounts including 401(k), health FSA, and dependent care FSA
- Relocation assistance to facilitate moving to Portland (if needed)
Additional Requirements
- Travel to conferences, vendors, and test sites as needed
- Intermittently able to work longer hours and weekends to support critical needs
Location: Portland, OR (on-site). Offices, lab, and shop located in Portland, Oregon.