Position Summary We are seeking a hands-on Application Security Engineer to join our Security Engineering team in Los Angeles. You will play a key role in safeguarding our products and infrastructure by running our bug bounty program, coordinating third-party penetration testing, handling internal security requests, participating in red/blue team exercises, and helping shape our emerging AI security practices.
Job Responsibilities - Bug Bounty Program Management: Operate and manage our public/private bug bounty programs on platforms such as HackerOne, including triaging incoming reports, interfacing with security researchers and triage teams, validating vulnerabilities, and driving remediation with engineering teams.
- Third-Party Penetration Testing: Coordinate and manage engagements with external penetration testing vendors, scope assessments, review deliverables, and track remediation to closure.
- Internal Security Testing Tickets: Own and execute internal security testing requests (tickets), including web/mobile application vulnerability assessments (black-box, grey-box, and white-box).
- Red Team / Adversarial Exercises: Participate in offensive and defensive security exercises (attack & defense drills) to strengthen our overall security posture.
- AI Security: Contribute to AI/LLM application security efforts, including LLM security testing, AI-assisted security automation, and assessing emerging AI-related threats.
- Provide actionable remediation guidance and clear communication to engineering teams, security leadership, and stakeholders.
Job Requirements - Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent practical experience).
- Solid understanding of the OWASP Top 10 and common web/mobile application vulnerabilities.
- Hands-on experience with web application vulnerability assessments and penetration testing.
- Familiarity with bug bounty platforms (e.g., HackerOne, Bugcrowd) and triage workflows.
- Strong communication skills; ability to translate technical findings into clear remediation guidance.
Nice to Have - Professional proficiency in Mandarin Chinese (to collaborate effectively with global / Chinese-speaking teams).
- Relevant certifications such as OSCP, GWAPT, or similar. Experience with AI/LLM security testing and security automation.
- Experience coordinating third-party pentest vendors and managing remediation lifecycles.
Benefits and Perks - Bonus eligible
- Healthcare (medical, dental, vision, prescription drugs)
- Health Savings Account with Employer Funding
- Flexible Spending Accounts (Healthcare and Dependent care)
- Company-Paid Basic Life/AD&D insurance
- Company-Paid Short-Term and Long-Term Disability
- Voluntary Benefit Offerings (Voluntary Life/AD&D, Hospital Indemnity, Critical Illness, and Accident)
- Employee Assistance Program
- Business Travel Accident Insurance
- 401(k) Savings Plan with discretionary company match and access to a financial advisor
- Vacation, paid holidays, floating holiday and sick days
- Employee discounts
- Free weekly catered lunch
- Dog-friendly office (available at select locations)
- Free gym access (available at select locations)
- Free swag giveaways
- Annual Holiday Party
- Invitations to pop-ups and other company events
- Complimentary daily office snacks and beverages
#LI-ED1
Pay Range
$91,000-$149,600 USD