Senior Application Security Engineer

Sift Science, Inc

$180K — $230K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in production software with security responsibilities.
  • Fluency in reading and reviewing Go or Rust code.
  • Strong grasp of application security vulnerabilities and design patterns.
  • Hands-on experience implementing security tools in developer workflows.
  • Proven ability to build and maintain widely adopted security libraries and tools.
  • Effective communicator of security risks to technical and non-technical stakeholders.

Responsibilities

  • Build secure patterns and standards for software vulnerabilities.
  • Manage dependency integrity and artifact trust in supply chains.
  • Collaborate with engineering on security in design and architecture.
  • Oversee integration of appsec tools into CI/CD processes.
  • Enhance security awareness among engineering through reviews and documentation.

Benefits

  • Relocation assistance to Marina Del Rey, CA or San Francisco available.
  • Occurrence of in-person collaborative meetings twice weekly and quarterly intensive meetings.
  • Opportunity to work in high-stakes environments, enhancing skillset.
  • Equity options included in the compensation package.
Full Job Description
In This Role, You'll:
  • Secure-by-default guardrails: Build the patterns, libraries, and standards for authentication, authorization, input handling, and cryptography that make whole classes of vulnerability hard to introduce. Ensure the secure path is the path of least resistance.
  • Software supply chain: Own dependency integrity, artifact signing, and build-pipeline trust. This matters especially for the self-managed and air-gapped deployments our customers run.
  • Threat modeling and secure design: Partner with engineering teams on new features and architectural changes across a distributed, polyglot system, and turn the results into concrete design decisions.
  • Developer-facing security tooling: Own the appsec toolchain in CI/CD: SAST, software composition analysis, secret scanning, and fuzzing. Tune it so developers get findings worth acting on, then work with the owning teams to drive remediation.
  • Raise engineering's security fluency: Make security knowledge something engineers pick up from design reviews, documentation, and working with you, not something they have to come ask for.

The Skillset You'll Bring:
  • 5+ years building production software, including direct security ownership of a codebase you shipped. You are a software engineer first, applying that skill to security.
  • Fluency reading and reviewing a compiled systems language, with depth in Go or Rust.
  • Strong grounding in application security: web and API vulnerability classes, authentication and authorization patterns, and applied cryptography, applied through threat modeling and design review on distributed systems.
  • Hands-on experience embedding security tooling (SAST, SCA, secret scanning) into developer workflows and CI/CD, tuned for signal over noise.
  • A track record of building security tooling or libraries that other teams actually adopted.
  • Clear communication with engineers and leadership. You can explain risk and tradeoffs to people who don't live in security.

Bonus Points:
  • Experience securing software that ships to customer-controlled, on-premise, or air-gapped environments.
  • Familiarity with software supply chain tooling and standards (Sigstore, SLSA, SBOM generation).
  • Fuzzing native or high-throughput data paths.
  • Exposure to regulated environments such as defense or aerospace.


Location:

SIFT's headquarters is in Marina Del Rey, CA (Next to LAX). We collaborate in person twice a week-on Mondays and Thursdays-and come together for a full week every two months. We are open to relocating candidates to LA or working from our San Francisco office for the right candidate.

Salary range: $180,000 - $230,000 per year. Plus equity and benefits.

Eligibility:

U.S. Citizenship Required: This position requires U.S. citizenship due to the nature of certain customer environments, security requirements, and access obligations associated with the role.

Similar Jobs

More Jobs at Sift Science, Inc

  • Growth Field Marketer
    $125K — $175K *
    San Francisco, CA 94112 (San Francisco County)
    Business Services
    In-Person
  • Software Engineer, Frontend
    $160K — $200K *
    San Francisco, CA 94112 (San Francisco County)
    Consumer Technology
    In-Person
  • Senior Software Engineer, Frontend
    $180K — $230K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person
  • Software Engineer, Frontend
    $160K — $200K *
    Marina Del Rey, CA 90292 (Los Angeles County)
    Information Technology
    In-Person
  • Deployment Strategist
    $125K — $175K *
    San Francisco, CA 94112 (San Francisco County)
    Technical Services
    In-Person

More Information Technology Jobs

Find similar Senior Application Security Engineer jobs: