Staff security engineer, application security
Agent
Ai Security
Application Security
Application Security Engineering
Data Security
DevOps
DevSecOps
Dynamic Application Security Testing
Engineer
Facilities Management
Gen Ai Security
Information Security
InfoSec
Management
Risk Management
Security
Security Automation
Security Engineer
Security Testing
Software Security
Static Application Security Testing
Job Description
WRITER is building security foundations for AI systems and enterprise AI applications, and this Staff security engineering role focuses on turning application and AI security into everyday practice. You will work across product and engineering to threat model LLM architectures, scale automated protections, and strengthen developer workflows through secure-by-default patterns.
What you’ll do
- Embed security into the AI platform by running threat modeling sessions with product teams and designing secure architectures for new features so security considerations influence product decisions from day one.
- Own and iterate on the application security program, including establishing and maintaining SAST/DAST scanning in CI/CD pipelines, performing security code reviews for critical changes, and building automation to detect vulnerabilities before they reach production.
- Collaborate with engineering teams to promote secure coding standards and create reusable security patterns and libraries that make secure development the default.
- Advise on security features and products that help protect customer environments as the security advocate and vision holder for customer protection.
- Integrate and leverage AI agents to increase velocity for both the security team and the broader engineering organization while proactively minimizing risk.
- Lead security assessments and penetration testing for WRITER’s applications, AI services, and APIs, identifying vulnerabilities across the tech stack and partnering with teams to remediate at scale.
- Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents.
- Stay ahead of evolving AI/ML and LLM-specific threats by researching attack vectors for generative AI and building defenses against emerging risks.
Requirements
- At least 4 years of hands-on experience in application security engineering, with a track record of securing large-scale production systems (experience in fast-growing or high-growth environments is a plus).
- Strong understanding of developer experience and developer workflows for shipping features, with a focus on reducing risk while maintaining engineering velocity.
- Technical proficiency in at least two programming languages: Python, Java, Go, or JavaScript/TypeScript, plus the ability to read and review code across multiple languages and assess both logic and security implications.
- Knowledge of security tooling and methodologies, including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices, with the ability to choose when automation outperforms manual review.
- Excellent communication skills to translate security concepts into clear recommendations for technical and non-technical audiences.
- A builder’s mindset focused on opportunities to automate, scale, and empower rather than introduce bottlenecks.
- Alignment with WRITER values: Connect, Challenge, and Own.
Technologies
- SAST, DAST, CI/CD
- Python, Java, Go, JavaScript/TypeScript
- LLMs, generative AI, AI/ML security
- DevSecOps
Compensation and location
Hybrid role in New York, NY. Compensation range is USD 183,000 - 240,000 per year, with reporting to the head of security engineering. This position is open to candidates at Mid, Sr., and Staff levels.
Benefits
- Generous PTO plus company holidays
- Medical, dental, and vision coverage for you and your family
- Paid parental leave for all parents (16 weeks)
- Fertility and family planning support
- Early-detection cancer testing through Galleri
- Flexible spending account and dependent FSA options
- Health savings account for eligible plans with company contribution
- Annual work-life stipends, including wellness stipend (gym, massage/chiropractor, personal training, etc.) and learning and development stipend
- Company-wide off-sites and team off-sites
- Competitive compensation, company stock options, and 401k