Senior / Staff Application Security Engineer

Suno

$230K — $330K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years of security engineering experience with a focus on application security.
  • Expertise in identifying and eliminating major vulnerability classes at the source, including code and API design.
  • Experience in building and implementing application security practices and secure SDLC tooling from the ground up.
  • Deep understanding of modern application stacks and proficiency with AWS.
  • Collaborative team player who can elevate security standards without hindering engineering workflows.
  • Proficient in writing and deploying production-quality code, beyond just reviewing others' work.
  • Curiosity about emerging threats related to AI and machine learning.

Responsibilities

  • Lead application security initiatives by executing threat modeling on features and services.
  • Identify and mitigate top vulnerabilities in the application layer such as injection and insecure APIs.
  • Establish and maintain a secure software development lifecycle including SAST, DAST, and secrets management.
  • Enhance the security of authentication and authorization processes product-wide.
  • Protect AI-focused application surfaces and address newly emerging vulnerabilities in generative features.
  • Collaborate with product and platform teams to integrate security measures during the design phase.
  • Set high standards for secure coding practices across engineering teams.

Benefits

  • Company equity package to share in company success.
  • 401(k) plan with 3% employer match and Roth options available.
  • Comprehensive medical, dental, and vision insurance plans with HSA and FSA options.
  • Generous unlimited PTO and sick time alongside 11 paid holidays.
  • 16 weeks of paid parental leave for new parents.
  • Creative education stipend to support ongoing learning.
  • Generous commuter allowance to ease travel costs.
  • Free in-office lunch five days a week.
Full Job Description
About the Role

We're looking for a Senior / Staff Application Security Engineer to own the security of how our product is built. You'll be the person who makes sure our code, APIs, and services are secure by design - threat-modeling the product, hardening the application layer, and building the AppSec practice from the ground up.

What You'll Do
  • Execute application security end to end: threat-model features and services, and drive remediation of the most significant risks.
  • Secure the application layer against the vulnerabilities that matter most - injection, broken authentication and authorization, and insecure APIs.
  • Build and run a secure SDLC: code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.
  • Harden authentication, authorization, and session/identity handling across the product.
  • Secure the AI-specific application surface - model and inference endpoints, prompt and input handling, and the new classes of vulnerability that come with shipping generative features.
  • Partner with product and platform engineering to design security in early and raise the security bar across the codebase.
  • Set the standard for how engineering reasons about and ships secure code.


What You'll Need
  • 6+ years in security engineering with deep, hands-on application-security expertise.
  • Strong command of the vulnerability classes that cause incidents and how to eliminate them at the source - code, API, and authz design.
  • A builder who has stood up AppSec practices and secure-SDLC tooling, not only operated established ones.
  • Fluent in modern application stacks and comfortable in AWS.
  • Able to work shoulder-to-shoulder with engineers and raise the bar without becoming a blocker.
  • Able to write and ship production-quality code, not only review it.
  • Curiosity about emerging AI/LLM threat classes and how to defend against them as the product evolves.
  • Nice to have: Consumer product at scale, secure-by-design work on generative-AI or ML product surfaces, and/or early security-hire experience.


Perks & Benefits for Full-Time Employees
  • Company Equity Package
  • 401(k) with 3% Employer Match & Roth 401(k)
  • Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options)
  • 11 Paid Holidays + Unlimited PTO & Sick Time
  • 16 Weeks of Paid Parental Leave
  • Creative Education Stipend
  • Generous Commuter Allowance
  • In-Office Lunch (5 days per week)


Additional Notes:
  • Applicants must be eligible to work in the US.
  • This role requires working onsite at one of our three offices.


Compensation:
  • $230,000 to 330,000

Similar Jobs

More Jobs at Suno

More Information Technology Jobs

Find similar Senior / Staff Application Security Engineer jobs: