Staff security engineer, application security
Job Description
WRITER is building enterprise AI applications at scale, and this Staff security engineer role focuses on making the platform secure by design. You will help shape how AI-powered products are protected across application security, AI infrastructure, and developer enablement, while evolving CI/CD security practices and leading security testing.
This hybrid position is based in Seattle, WA and reports to the head of security engineering. If you have hands-on experience securing large-scale production systems and can balance security risk reduction with engineering velocity, this role aligns with your approach to building and scaling security foundations.
Responsibilities
- Run threat modeling sessions with product teams, design secure architectures for new features, and ensure security considerations are part of product decisions from day one
- Own and evolve WRITER’s application security program, including establishing and maintaining SAST/DAST scanning in CI/CD pipelines, performing security code reviews for critical changes, and building automation to prevent vulnerabilities from reaching production
- Partner with engineering teams to define and champion secure coding standards, plus create reusable security patterns and libraries that enable secure-by-default development
- Recommend security features and products to help secure customer environments, serving as a vision and advocacy partner for customer protection
- Integrate and leverage AI agents to increase security team and engineering org velocity while proactively minimizing risk
- Lead security assessments and penetration testing across WRITER’s applications, AI services, and APIs, identifying vulnerabilities across the stack and working with teams to remediate issues at scale
- Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
- Research emerging threats in the AI/ML security landscape, including LLM and generative AI attack vectors, and proactively build defenses against new risks
Requirements
- Minimum 4 years of hands-on application security engineering experience, with a track record securing large-scale production systems (bonus for fast-growing startups or high-growth environments)
- Understanding of developer experience and developer workflows for shipping features, with focus on reducing risk while supporting engineering velocity
- Technical expertise in at least two programming languages: Python, Java, Go, JavaScript/TypeScript, including ability to review code across multiple languages with both business logic and security implications
- Knowledge of security tools and methodologies such as SAST/DAST, vulnerability management platforms, security testing frameworks, and DevSecOps practices, with judgment on when automation outperforms manual review
- Excellent communication skills to translate complex security concepts for technical and non-technical audiences and drive action through clear recommendations
- A builder mindset focused on automation, scaling, and enabling teams rather than creating bottlenecks
- Alignment with WRITER values: Connect, Challenge, and Own
- Open to Mid, Sr., and Staff level candidates
Technologies
- SAST, DAST, CI/CD
- Python, Java, Go, JavaScript/TypeScript
- DevSecOps, LLMs, generative AI, AI agents
- APIs, vulnerability management platforms, security testing frameworks
Compensation and location
- Location: Seattle, WA (hybrid)
- Salary: USD 183,000 - 240,000 per year
Benefits
- Generous PTO plus company holidays
- Medical, dental, and vision coverage for you and your family
- Paid parental leave for all parents (16 weeks)
- Fertility and family planning support
- Early-detection cancer testing through Galleri
- Flexible spending account and dependent FSA options
- Health savings account for eligible plans with company contribution
- Annual work-life stipends for Wellness (gym, massage/chiropractor, personal training, etc.)
- Annual work-life stipend for Learning and development
- Company-wide off-sites and team off-sites
- Competitive compensation, company stock options and 401k