Match your resume skills with our AI powered skill match!
Questions interviewers often ask for this role, with sample answers.
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
Establish and mature a company-wide secure SDLC and application security program, integrating practical security requirements, testing tools, vulnerability management, and secure supply-chain controls into engineering workflows. Partner with development, platform, product, and leadership teams on threat modeling, remediation, developer enablement, incident response, and program metrics.
Shield AI is a venture-backed defense-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include Hivemind autonomy software, V-BAT and X-BAT aircraft, and Aechelon simulation and synthetic reality technologies. With offices and facilities across the U.S., Europe, the Middle East, and Asia-Pacific, Shield AI’s technology actively supports operations worldwide. For more information, visit www.shield.ai. Follow Shield AI on LinkedIn, X, Instagram, and YouTube.
We are seeking a Staff Application Security Engineer to build and advance a scalable, developer-centered application security program. This role will establish company-wide secure software development lifecycle (SDLC) policy and standards, translate them into practical engineering practices, and partner directly with product, platform, and development teams to improve secure development and software supply-chain maturity.
The successful candidate combines technical application-security depth with the programmatic leadership to drive enterprise-wide improvement. You will help teams build, test, package, release, and maintain secure software while ensuring security controls are practical, measurable, and integrated into existing engineering workflows.
This is a Staff level individual-contributor role with significant influence across engineering, security, product, and technology leadership.
* Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.
* Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.
* Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.
* Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.
* Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.
* Evaluate, implement, tune, and operationalize application-security tooling, including:* Static application security testing (SAST)
* Dynamic application security testing (DAST)
* Software composition analysis (SCA)
* Secrets detection
* Infrastructure-as-code security scanning
* Container and image security scanning
* API and cloud-native application security controls
* Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.
* Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.
* Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.
* Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.
* Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.
* Mature software supply-chain security practices, including:* Machine-readable software bills of materials (SBOMs)
* Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications
* Build and release provenance
* Artifact, package, container-image, and binary signing
* Artifact verification and trusted promotion processes
* Secure artifact repositories and package registries
* Approved dependency sources and package integrity verification
* SLSA-aligned build integrity, provenance, and release controls
* Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.
* Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
* Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.
* Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.
* Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
* Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.
NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.
#LI-KE1
#LC
Full-time regular employee offer package:
Pay within range listed + Bonus + Benefits + Equity
Temporary employee offer package:
Pay within range listed above + temporary benefits package (applicable after 60 days of employment)
Salary compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, licenses and certifications, and specific work location. All offers are contingent on a cleared background and possible reference check. Military fellows and part-time employees are not eligible for benefits. Please speak to your talent acquisition representative for more information.
###
Shield AI is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or Veteran status. If you have a disability or special need that requires accommodation, please let us know.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 216,306+ Jobs in Application Security Engineer
Answer easy questions
216,306+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”