Staff security engineer, application security
Ai Security
Application Security
Application Security Engineering
Artificial Intelligence
Ci/cd Security
Data Security
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
Risk Management
Secure Application Development
Security
Security Automation
Security Engineering
Security Standards
Security Testing
Software Security
Solution Architecture
Static Application Security Testing
Threat Modeling
Job Description
WRITER is building security foundations for AI systems at enterprise scale, and this role helps make that foundation real across applications, AI infrastructure, and developer workflows. Based in San Francisco, CA (hybrid), you will lead application security efforts that support shipping securely without slowing engineering teams down.
What you’ll build and own
- Embed security into the AI platform by running threat modeling sessions with product teams and shaping secure architectures for new features so security considerations are included from day one.
- Own and evolve WRITER’s application security program, including establishing and maintaining SAST/DAST scanning in CI/CD pipelines, performing security code reviews for critical changes, and building automation to catch vulnerabilities before they reach production.
- Partner with engineering teams to promote secure coding standards and create reusable security patterns and libraries that help developers build securely by default.
- Design and recommend security features and products that help protect customer environments, acting as the advocate and vision for customer security.
- Integrate and leverage AI agents to increase velocity for the security team and the broader engineering org, supporting proactive risk reduction while products are built.
- Lead security assessments and penetration testing across WRITER’s applications, AI services, and APIs, identifying vulnerabilities across the stack and coordinating remediation at scale.
- Design and implement security controls for data pipelines, model training environments, and customer-facing AI agents.
- Stay ahead of emerging threats in AI/ML security by researching LLM and generative AI attack vectors and proactively building defenses against novel risks.
What you’ll bring
- 4+ years of hands-on experience in application security engineering, with a track record of securing large-scale production systems (bonus for fast-growing startups or high-growth environments).
- A strong understanding of developer experience and workflows, with an approach that reduces risk while respecting engineering velocity.
- Technical expertise in at least two programming languages: Python, Java, Go, JavaScript/TypeScript, including the ability to read and review code across languages with awareness of business logic and security implications.
- Knowledge of security tools and methodologies such as SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices, with judgment on when automation is preferable to manual review.
- Excellent communication skills to translate complex security concepts for technical and non-technical audiences and drive actionable recommendations.
- A builder mindset focused on automation, scaling, and enablement rather than creating bottlenecks, with the view that security enables the business.
- Alignment with WRITER’s values: Connect, Challenge, and Own (end-to-end responsibility for platform security).
- This position is open to Mid, Sr., and Staff level candidates.
Compensation and key technologies
Salary: USD 183,000 - 240,000 per year.
Technologies: Python, Java, Go, JavaScript/TypeScript, SAST, DAST, CI/CD, AI agents, LLMs, generative AI, AI/ML.
Benefits
- Generous PTO, plus company holidays
- Medical, dental, and vision coverage for you and your family
- Paid parental leave for all parents (16 weeks)
- Fertility and family planning support
- Early-detection cancer testing through Galleri
- Flexible spending account and dependent FSA options
- Health savings account for eligible plans with company contribution
- Annual work-life stipends for wellness (gym, massage/chiropractor, personal training, etc.)
- Annual work-life stipends for learning and development
- Company-wide off-sites and team off-sites
- Competitive compensation, company stock options and 401k