Lead Application Security Engineer, Code to Cloud
Job Description
QXO is hiring a Lead Application Security Engineer to own application security end to end, with responsibility that spans the full software delivery lifecycle. This role focuses on delivering continuous security coverage from source code to pipeline execution and onward through cloud runtime, with an emphasis on automation that keeps false positives at levels engineers can trust.
Based in Vancouver, WA, this position is onsite. The salary range is USD 101,300 to 172,000 per year, and the role requires 8+ years of relevant experience.
What you will do
- Own the scanning and posture platform coverage across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, including routing, deduplication, and prioritization of findings, plus owner resolution, SLA tracking, and closure verification.
- Build and run policy-based blocking controls in pull requests and CI/CD pipelines, using policy-as-code applied centrally and scoped to repository tiering so future repositories inherit coverage. Turn blocking on only once baselines are triaged and false positives are below the agreed threshold.
- Author application security standards, secure design patterns, and remediation SLAs, manage the exception and risk-acceptance workflow, and report on risk reduced rather than finding counts. Make threat modeling repeatable with templates and AI-assisted triage that produces testable requirements.
- Participate in architecture and design reviews with principal engineers, including decisions about token versus service identity mechanisms, object-level authorization across list endpoints, and preventing services from using authorization attributes supplied by callers. Review third-party integrations before production.
- Set the technical bar for the practice by coaching the champions network and third-party testing partners, and mentoring engineers added to the team. Provide timely, constructive explanations to engineering teams about what a finding does and does not mean.
- Own security testing of the running application, partnering with developers on remediation and verifying fixes on retest. Lead response efforts when a critical vulnerability or exploit is discovered.
- Lead security integration of acquired engineering environments by bringing their repositories, pipelines, and cloud accounts under coverage without stopping delivery.
Requirements
- 8+ years in application security, product security, DevSecOps, or security engineering, with most experience being hands-on rather than advisory.
- Experience owning an enterprise-scale security program across multiple teams and stakeholders with limited oversight, including setting standards and reviewing the work of other engineers.
- Depth in a cloud-native application protection or application security posture platform such as Wiz, Snyk, Prisma Cloud, or Orca, including writing policy and using its API.
- Shipped pipeline enforcement, including PR and CI/CD policy-based blocking, security policy-as-code, and moving controls from advisory to blocking.
- Threat modeling experience using STRIDE or an equivalent applied to real systems, extended with MITRE ATLAS and LLM risk taxonomies for AI-enabled systems.
- Architecture-level security judgment for distributed authorization design, including trust boundaries, token validation, service-to-service identity, and object-level access control.
- Approachable, responsive, and constructive communication under pressure, including the ability to flag launch risks without becoming an obstacle to delivery.
- An automation-first, AI-forward approach to work, plus a defensible view on securing AI itself, including validating AI-generated code and agentic risk such as prompt injection, tool permissions, and the MCP supply chain.
- Dynamic testing experience via DAST, API security testing, or hands-on offensive work, and cloud security depth in a major public cloud (with Google Cloud a plus).
- Coding ability in Python, Go, or TypeScript, with evidence-backed, defensible implementations.
Technologies
- Wiz, Snyk, Prisma Cloud, Orca
- STRIDE, MITRE ATLAS
- Python, Go, TypeScript
- Google Cloud
- DAST, MCP
Compensation and benefits
- Base pay range: $101,300 - $172,000 per year
- Annual performance bonus
- 401(k) with employer match
- Medical, dental, and vision insurance
- PTO, company holidays, and parental leave
- Paid Time Off/Paid Sick Leave: 15 days of paid time off during the first year (15 days; 4.62 hours for every 80 hours worked) with increased accruals after five years
- Paid training and certifications
- Legal assistance and identity protection
- Pet insurance
- Employee assistance program (EAP)
Education & certifications
- Bachelor’s in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred
- Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect
- CSSLP, GWAPT, OSWE, or OSCP a plus
What you will earn
- Base pay range: $101,300 - $172,000
- Annual performance bonus
- 401(k) with employer match
- Medical, dental, and vision insurance
- PTO, company holidays, and parental leave
- Paid Time Off/Paid Sick Leave details: applicants can expect to accrue 15 days during the first year (4.62 hours for every 80 hours worked), with increased accruals after five years
- Paid training and certifications
- Legal assistance and identity protection
- Pet insurance
- Employee assistance program (EAP)