Anomaly - Application Security Engineer
Requirements
• 4+ years of experience in Application Security, Product Security, Security Engineering, or Software Engineering with a strong security focus • Strong understanding of common application security vulnerabilities and secure coding principles, including OWASP Top 10 risks • Experience conducting threat modeling, security reviews, and vulnerability assessments for web applications and APIs • Familiarity with modern application security tooling, including SAST, DAST, dependency scanning, container scanning, and CI/CD security controls • Experience securing cloud-native applications running on AWS • Proficiency in at least one modern programming language such as Python, Go, Java, TypeScript, or similar • Experience working closely with engineering teams to drive remediation and improve security posture • Understanding of authentication, authorization, cryptography, and secure system design principles • Experience operating in regulated environments such as healthcare, fintech, or enterprise SaaS is a plus • Familiarity with AI/ML systems and emerging security considerations around LLMs, agents, and model-integrated applications is a plus • Ability to balance security, engineering velocity, and business priorities in a collaborative startup environment
Responsibilities
• Embed security throughout the software development lifecycle, from architecture and design reviews through deployment and monitoring • Perform application security assessments, threat modeling, and code reviews for new and existing products • Develop and maintain security tooling, automation, and guardrails to help engineers identify and remediate vulnerabilities early • Manage vulnerability detection and remediation processes across applications, APIs, cloud infrastructure, and third-party dependencies • Partner with engineering teams to improve secure coding practices and security awareness • Design and implement security controls for cloud-native environments running on AWS • Evaluate and improve authentication, authorization, secrets management, and data protection mechanisms across our products • Build and maintain security monitoring and detection capabilities for application and infrastructure environments • Conduct security testing, including static analysis, dynamic analysis, dependency scanning, and penetration testing coordination • Support customer security reviews and audits by providing technical expertise related to product and application security • Help define security standards and best practices for the development and deployment of AI-powered systems
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT