Application Security Engineer

Cerebras Systems

$130K — $160K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Strong fundamentals in application or product security with hands-on vulnerability management experience.
  • In-depth knowledge of vulnerability classes and exploitation techniques relevant to the tech stack.
  • Proficient in reading code and collaborating with software engineers for successful remediation.
  • Experience with application security tools including SAST, DAST, and various scanning technologies.
  • Familiarity with vulnerability prioritization concepts and techniques like CVSS and threat intelligence.
  • Ability to manually investigate security findings beyond relying on scanners.
  • Proficient in automating workflows using languages like Python or Go.

Responsibilities

  • Own and enhance the vulnerability management process across a range of technologies.
  • Utilize AI agents for advanced vulnerability discovery and remediation strategies.
  • Conduct thorough analysis of vulnerabilities considering exploitability and business impact.
  • Collaborate with engineering teams to address vulnerabilities effectively within risk-based SLAs.
  • Develop automation processes for vulnerability handling and reporting tasks.
  • Identify and rectify systemic vulnerability patterns in collaboration with engineering teams.
  • Fortify application security capabilities, including various scanning and monitoring technologies.

Benefits

  • Opportunity to work at the forefront of AI advancements.
  • Dynamic environment encouraging innovative security practices.
  • Collaboration across multifunctional teams including engineering and IT.
  • Focus on strategic vulnerability management rather than rote ticket handling.
Full Job Description
About the Role

We are looking for an Application Security Engineer with a strong focus on Vulnerability Management to help secure Cerebras software, infrastructure, and AI platforms.

You will own and evolve key parts of our vulnerability management program from vulnerability discovery and risk prioritization through remediation and verification. This is not a ticket-management role. We are looking for an engineer who can understand vulnerabilities in context, work directly with engineering teams, automate repetitive security work, and help eliminate classes of vulnerabilities rather than simply track individual findings.

You will work closely with Engineering, Infrastructure, and IT teams to identify vulnerabilities across our products and environments and drive them to meaningful remediation.
Responsibilities
  • Own and continuously improve vulnerability management across applications, software dependencies, containers, operating systems, cloud infrastructure, and externally exposed services.
  • Use AI agents and advanced security models to augment vulnerability discovery, code analysis, adversarial testing, prioritization, and remediation.
  • Analyze vulnerabilities beyond scanner severity by considering exploitability, exposure, affected assets, available mitigations, and business impact.
  • Partner directly with engineering teams to triage findings, determine appropriate remediation, and drive vulnerabilities to closure within risk-based SLAs.
  • Build automation for vulnerability ingestion, deduplication, enrichment, prioritization, assignment, remediation tracking, and reporting.
  • Identify systemic vulnerability patterns and work with engineering teams to address root causes rather than repeatedly fixing individual findings.
  • Operate and improve application security capabilities including SAST, SCA, secrets detection, container scanning, infrastructure scanning, and external attack-surface monitoring.
  • Validate security findings through technical investigation and hands-on testing, distinguishing exploitable vulnerabilities from false positives and low-risk findings.
  • Perform targeted application security reviews and testing for high-risk services and features.
  • Help integrate security controls into CI/CD and developer workflows while minimizing unnecessary friction for engineering teams.
  • Develop metrics and reporting that provide meaningful visibility into vulnerability exposure, remediation performance, recurring vulnerability classes, and security risk.
  • Evaluate and integrate new security technologies as our software and infrastructure environments evolve.
  • Partner with security and engineering teams on incident response when vulnerabilities are actively exploited or require urgent remediation.
Skills & Qualifications

We are looking for candidates who:
  • Have strong application security or product security fundamentals and hands-on experience with vulnerability management.
  • Understand common vulnerability classes and exploitation techniques across web applications, APIs, authentication systems, cloud services, containers, and software supply chains.
  • Can read and reason about code and work effectively with software engineers on practical remediation.
  • Have experience with vulnerability scanning and application security technologies such as SAST, SCA, DAST, secrets scanning, container scanning, or CSPM.
  • Understand vulnerability prioritization concepts including CVSS, exploitability, asset criticality, internet exposure, compensating controls, and threat intelligence.
  • Are comfortable investigating security findings manually rather than relying exclusively on scanner output.
  • Can automate security workflows using languages such as Python, Go, or similar scripting/programming languages.
  • Have experience integrating security tooling into CI/CD and modern software development workflows.
  • Are comfortable working with Linux, Git, containers, and cloud environments.
  • Can communicate security risk clearly to both security specialists and engineering teams.
  • Approach security with an automation-first mindset and look for scalable solutions instead of manual processes.
Preferred Qualifications

Experience in one or more of the following areas is a plus:
  • Application Security or Security engineering background.
  • Securing AI/ML platforms, inference services, or large-scale compute infrastructure.
  • Building or operating vulnerability management programs at scale.
  • AWS, Kubernetes, Docker, and cloud-native environments.
  • Software supply-chain security and dependency management.
  • GitHub and CI/CD security.
  • Threat modeling and secure design reviews.
  • Penetration testing or offensive security.
  • External attack-surface management.
  • Vulnerability research or exploit validation.
  • Security data pipelines, APIs, and workflow automation.
  • Using LLMs, AI agents, or AI-assisted security tooling for vulnerability research, code analysis, penetration testing, or remediation.
What Success Looks Like

You will help Cerebras move beyond simply finding vulnerabilities toward an engineering-driven vulnerability management program where:
  • The vulnerabilities that create the most meaningful risk are identified and prioritized quickly.
  • Engineering teams receive actionable findings with clear remediation guidance.
  • High-risk vulnerabilities are consistently remediated within defined SLAs.
  • Security findings are increasingly validated, prioritized, and routed automatically.
  • Recurring vulnerability classes are addressed systematically.
  • AI and automation reduce manual security work and accelerate both vulnerability discovery and remediation.

Most importantly, you will help build security processes that scale with the speed at which Cerebras builds and deploys some of the most advanced AI systems in the world.ADD DESCRIPTION HERE

Apply today and become part of the forefront of groundbreaking advancements in AI!

Similar Jobs

More Jobs at Cerebras Systems

More Information Technology Jobs

Find similar Application Security Engineer jobs: