CAIS - Lead Application Security Engineer
Requirements
• Experience in application or product security teams. A software engineering background is • Ability to read and reason about production code and hold your own with senior engineers, with working knowledge of Java/Kotlin and JavaScript/TypeScript (React). • Solid AWS security experience, including securing cloud-native, containerized environments (e.g. EKS). • Hands-on experience with security tooling across the SDLC, such as SAST, DAST, and dependency or container scanning (specific products are not important). • Demonstrated experience driving threat modeling and leading security architecture and design reviews. • Proven ability to lead engineering and security teams in adopting AI tools and automated workflows when it comes to security as part of the SDLC . • A confident, collaborative communicator who partners effectively with engineers and product owners and explains risk clearly to both technical and non-technical audiences. • A builder's mindset, you are energized by growing an application security practice from an early stage, eager to experiment and collaborative along the way.
Responsibilities
• Secure Software Development & Architecture • Own security elements of the software development lifecycle, designing and implementing automated controls within CI/CD, including SAST, DAST, dependency and container security scanning. • Conduct security architecture and design reviews across product and platform areas, surfacing risk early and providing clear, actionable remediation paths. • Drive CAIS's threat modeling strategy, establishing it as a repeatable practice across teams rather than a one-off exercise. • Vulnerability Management & Engineering Partnership • Triage, validate, and prioritize findings, coordinating remediation through to resolution with clear ownership and follow-through. • Liaise with key vendors on penetration testing, vulnerability scanning, and threat modeling, translating external findings into prioritized action. • Partner with engineers and product owners to embed security pragmatically into design, development, and release, supporting teams without becoming a blocker. • Provide secure coding guidance and clear documentation that helps teams understand risk and apply secure development practices independently. • Level up CAIS's security capability across the tech stack, experimenting with new tooling, automation, and AI-assisted workflows as the practice grows.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT