Smartsheet

Senior Security Engineer II, Application Security (Remote Eligible)

Smartsheet$175K — $245K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in application security with hands-on experience in product security roles.
  • Fluency in modern programming languages (Java, Python, TypeScript/JavaScript, Go, or Ruby).
  • Extensive knowledge of AI-integrated applications and securing AI systems.
  • Experience conducting thorough security reviews, threat modeling, and architecture assessments.
  • Proficient in manual web application testing and confirming vulnerabilities beyond automated tools.
  • Active involvement in bug bounty programs with experience in researcher communication.
  • Familiarity with CI/CD pipeline security operations and cloud security fundamentals.

Responsibilities

  • Conduct security reviews and threat modeling for AI-integrated product features.
  • Own end-to-end security assessments for high-risk features during product development.
  • Operate and enhance security scanning within GitLab CI/CD pipelines.
  • Serve as the validation layer for the bug bounty program, assessing researcher submissions.
  • Build automation tools and integrations to scale security efforts and risk visibility.
  • Engage with engineering teams to influence design decisions and close security gaps before product release.
  • Provide security feedback that improves the developer experience and reduces false positives.

Benefits

  • Employer subsidized medical, vision, and dental coverage for full-time employees.
  • 401k match to assist saving for retirement.
  • Flexible Time Away Program, plus Sick Time Off.
  • 12 paid holidays and up to 24 weeks of Parental Leave per year.
  • Professional growth opportunities through access to Udemy online courses.
  • Telecommuting options from any registered location in the U.S.
  • Company funded perks including counseling membership and retail discounts.
Full Job Description
You Will:
  • Secure AI Systems and Use AI to Scale Security: Conduct security reviews and threat modeling of AI-integrated product features (LLM workflows, agentic pipelines, model APIs) with working knowledge of AI-specific risk classes including prompt injection, model manipulation, and runtime control gaps; and in parallel, deploy AI and automation as a force multiplier by building tooling, pipelines, and integrations that extend the team's reach, accelerate triage, and drive risk visibility at a scale manual effort alone cannot achieve.
  • Deliver Application Security Reviews: Own end-to-end security assessments for high-risk features and services (threat modeling, architecture review, targeted code review, and security testing) embedded in the product development lifecycle. Work directly with engineering teams to surface and close risk before it ships, with enough technical credibility to influence design decisions, not just document findings.
  • Advance CI/CD Pipeline Security: Operate and evolve the security scanning controls embedded in Smartsheet's GitLab pipelines (SAST, SCA, secrets, IaC scanning). Tune tools, engage teams on findings, and build automation that reduces false positive burden and improves how developers experience security feedback.
  • Run Bug Bounty Operations: Serve as the expert validation layer for Smartsheet's bug bounty program, reproducing and assessing complex, multi-step researcher submissions requiring authenticated context and deep platform knowledge, making defensible severity and payout decisions, and owning program operations including researcher engagement, metrics, and continuous improvement.

You Have:
  • Experience: 8+ years in application security, with a track record of owning complex, multi-capability work in a product security or AppSec engineering role.
  • Software engineering foundation: Fluent in one or more modern languages (Java, Python, TypeScript/JavaScript, Go, Ruby, or equivalent); you identify security-relevant patterns without relying on tooling and write automation that others adopt.
  • AI security: Hands-on experience securing AI-integrated applications (LLM systems, agentic workflows, model APIs) and demonstrated experience deploying AI and automation to scale security functions or extend team reach. You bring both skill sets.
  • Security review depth: Threat modeling, architecture review, and code review for complex SaaS features; you produce findings engineering teams can act on and carry enough technical credibility to influence design decisions, not just document them.
  • Manual web application testing: Independent, hands-on validation of complex, multi-step authenticated vulnerabilities; you confirm what scanners flag and find what they miss.
  • Bug bounty experience: Operator, active researcher, or both; direct experience with triage, severity calibration, and researcher communication.
  • CI/CD pipeline security: Working knowledge of SAST, SCA, secrets, and IaC scanning in modern pipelines, with experience engaging teams on findings and improving signal quality.
  • Cloud security fundamentals: Working knowledge of AWS, GCP, or Azure sufficient to tie application-layer risk to the infrastructure it runs on; you understand where the application ends and the cloud begins.
  • Legally eligible to work in the U.S. on an ongoing basis
  • BS or MS in Computer Science, a related field, or equivalent industry experience

NICE TO HAVE:
  • Experience with agentic security, MCP security, or adversarial evaluation of autonomous AI systems.
  • GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration.
  • Active bug bounty researcher with published findings, CVE credits, or hall of fame recognition.
  • Penetration testing program management experience: scope definition, vendor coordination, and finding validation with third-party testers.


Current US Perks & Benefits:
  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range

$175,000-$245,000 USD

About Smartsheet

Smartsheet is a software as a service (SaaS) company that provides businesses with collaboration and work management tools. The company's platform allows teams to manage and automate workflows, projects, and processes. Smartsheet's software is used by over 90% of the Fortune 100 companies and has over 15 million registered users. The company was founded in 2005 and is headquartered in Bellevue, Washington.
Learn more about Smartsheet
Size
2,539 employees
Market Cap
$4.9 billion
Industry
Net Income
-$114.4 million
Founded
2005
5 Year Trend
+52.4%
Revenue
$354.1 million
NASDAQ

Similar Jobs

More Jobs at Smartsheet

More Information Technology Jobs

Find similar Senior Security Engineer II, Application Security (Remote Eligible) jobs: