Lead Application Security Engineer, Code to Cloud

QXO

• $101K — $172K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in application security, product security, DevSecOps, or security engineering, primarily hands-on.
  • Experience leading an enterprise-scale security program with minimal oversight.
  • Proficient in a cloud-native application protection platform such as Wiz, Snyk, or Prisma Cloud, with direct policy writing experience.
  • Experience implementing policy-based security controls in CI/CD pipelines.
  • Knowledgeable in threat modeling, particularly using methodologies like STRIDE and MITRE ATLAS.
  • Strong architectural security judgment for distributed systems design and authorization processes.
  • Hands-on experience with dynamic testing of applications and APIs.
  • Proficient in coding with Python, Go, or TypeScript.

Responsibilities

  • Own the end-to-end application security scanning and posture platform, ensuring trust and accuracy.
  • Implement policy-based controls in CI/CD pipelines, ensuring proactive security measures without impeding engineering.
  • Develop application security standards and lead risk management processes, focusing on risk reduction rather than just issue counts.
  • Participate in architectural reviews, influencing secure design decisions in collaboration with principal engineers.
  • Mentor security champions and guide third-party testers, fostering a collaborative security culture.
  • Lead security testing for running applications, ensuring identified vulnerabilities are mitigated effectively.
  • Integrate acquired environments into the security framework, enhancing security without hampering delivery timelines.

Benefits

  • Annual performance bonus.
  • 401(k) with employer match.
  • Medical, dental, and vision insurance.
  • Paid Time Off, company holidays, and parental leave.
  • Accrue 15 days of paid time off in the first year with increased accruals after five years.
  • Paid training and certifications support.
  • Legal assistance and identity protection programs available.
  • Pet insurance offered as part of benefits package.
  • Employee assistance program (EAP) for mental health and wellness support.
Full Job Description
As a Lead Application Security Engineer, Code to Cloud at QXO, you'll be the recognized subject matter expert for application security across the company and own the engineering behind Code to Cloud: continuous security coverage across QXO's software delivery lifecycle, from source code through pipeline execution to cloud runtime.

What you'll do:

  • Own the scanning and posture platform end to end across secrets, SAST, SCA, infrastructure-as-code, container images, and cloud runtime, at a false-positive rate engineers trust. Build the automation that routes, deduplicates, and prioritizes findings, with owner resolution, SLA tracking, and closure verification.
  • Build and run policy-based blocking controls in pull requests and CI/CD pipelines, as policy-as-code applied centrally and scoped to repository tiering, so coverage inherits to future repositories. Turn a gate on only when the baseline is triaged and false positives are under bar, and never block a team without a path forward.
  • Author the application security standards, secure design patterns, and remediation SLAs QXO builds against, own the exception and risk-acceptance workflow, and report on risk reduced rather than finding counts. Make threat modeling repeatable through templates and AI-assisted triage, producing testable requirements.
  • Sit in architecture and design reviews with principal engineers and reach a decision in the room: where a gateway-validated token stops being sufficient and service identity needs its own mechanism, how object-level authorization survives a list endpoint, and why a service must never take an authorization attribute from its caller. Review third-party integrations before production.
  • Set the technical bar for the practice: coach, review, and direct the security work of the champions network and third-party testing partners, and mentor engineers added to the team. Be the person engineering calls, explaining what a finding means and what it does not, so a blocked developer gets an answer the same day.
  • Own security testing of the running application, not just its source, and work with developers to remediate what it finds, verifying on retest. Lead the response when a critical vulnerability or exploit drops.
  • Lead the security integration of acquired engineering environments, bringing their repositories, pipelines, and cloud accounts under coverage without stalling delivery.

What you'll bring:

  • 8+ years in application security, product security, DevSecOps, or security engineering, most of it hands-on rather than advisory.
  • Hands-on experience owning an enterprise-scale security program across multiple teams and stakeholder groups with limited oversight, including setting standards others follow and reviewing the work of other engineers.
  • Depth in a cloud-native application protection or application security posture platform such as Wiz, Snyk, Prisma Cloud, or Orca. You have written policy and built on its API, not just read dashboards.
  • Pipeline enforcement you have actually shipped: policy-based blocking in pull requests and CI/CD, security policy-as-code, and the harder part, moving a control from advisory to blocking without an engineering revolt.
  • Threat modeling you have run, not just studied. STRIDE or an equivalent applied to real systems, extended with MITRE ATLAS and the LLM risk taxonomies where classical categories fall short on AI-enabled systems.
  • Architecture-level security judgment. You can hold your own with a principal engineer on authorization design in a distributed system: trust boundaries, token validation, service-to-service identity, and object-level access control.
  • Approachable, responsive, and constructive under pressure. You can tell a team their launch has a problem without becoming the reason they route around security.
  • An automation-first, AI-forward way of working, and a defensible view on securing AI itself: validating AI-generated code, and agentic risk including prompt injection, tool permissions, and the MCP supply chain.
  • Dynamic testing of running applications and APIs through DAST tooling, API security testing, or hands-on offensive work, and cloud security depth in a major public cloud, Google Cloud a plus.
  • Coding ability in Python, Go, or TypeScript, and writing that is tight, evidence-backed, and defensible when challenged.


Education & Certifications
  • Bachelor's in computer science, information assurance, MIS, or equivalent practical experience; advanced degree preferred. Google Cloud certifications preferred, particularly Professional Cloud Security Engineer, DevOps Engineer, or Architect. CSSLP, GWAPT, OSWE, or OSCP a plus.

What you'll earn

  • Base pay range: $101,300 - $172,000
  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • PTO, company holidays, and parental leave
  • Paid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.
  • Paid training and certifications
  • Legal assistance and identity protection
  • Pet insurance
  • Employee assistance program (EAP)


To comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.

Please contact [email protected] if you have any questions related to this job posting.

Salary Range:

USD $101,300.00 - USD $172,000.00 /Yr.

Similar Jobs

More Jobs at QXO

More Information Technology Jobs

Find similar Lead Application Security Engineer, Code to Cloud jobs: