Censys

Staff Application Security Engineer

Censys$172K — $233K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in Security Engineering, DevSecOps, SRE, or related roles
  • Expertise in securing Kubernetes environments and supply chain protections
  • Strong experience with AppSec tooling integrated into CI/CD pipelines
  • Understanding of attacker tactics and frameworks like MITRE ATT&CK
  • Proficiency in cloud services, especially GCP, and Infrastructure-as-Code tools
  • Scripting skills in languages like Python or Bash
  • Strong communication skills and ability to balance security practices with developer needs

Responsibilities

  • Own and drive the AppSec/DevSecOps program roadmap across engineering
  • Design, build, and maintain DevSecOps tooling in Kubernetes and GCP
  • Lead the integration of security into CI/CD pipelines
  • Deliver capabilities that reduce developer cognitive load and risk
  • Set security architecture direction for AI/ML workflows
  • Partner with CorpSec on security and compliance initiatives
  • Provide technical leadership and mentorship to engineers
  • Participate in shared on-call rotation for production support

Benefits

  • Equity and bonus eligibility
  • Health, dental, and vision coverage
  • Retirement plan with company contribution
  • Parental leave and mental health benefits
  • Flexible PTO policy
  • Professional development stipend for continuous learning
Full Job Description
Location:

This position is remote within the United States or Canada.

Role Summary:

Censys is seeking a Staff Application Security Engineer to join our Infrastructure and Operations Platform (SRE) team. In this role, you'll own the application security strategy for how Censys builds and ships software - designing the secure paths, guardrails, and automation that let our engineers develop and deploy quickly, confidently, and securely. You'll set technical direction across the software lifecycle, from infrastructure-as-code and container security to secure deployment workflows and the security of our AI/ML-enabled services. As a security company, we hold ourselves to the standard we help our customers achieve; this role is central to making that real. We expect all of our employees to consider customer happiness as our primary goal and to come to work every day eager to learn and educate, helping to make us a better organization every day.

What You'll Do:
  • Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates
  • Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads
  • Lead the integration of security into CI/CD pipelines - code scanning, secret detection, software composition analysis, and infrastructure policy enforcement - partnering with engineering teams to adopt them without friction
  • Deliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organization
  • Set the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance tracking
  • Partner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracy
  • Provide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teams
  • Participate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readiness

What You'll Bring:
  • 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teams
  • Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane)
  • Strong experience with Application Security tooling - dependency scanning, static analysis, and policy enforcement - integrated into CI/CD pipelines such as GitHub Actions and ArgoCD, and the ability to bridge engineering practices with Security Operations
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs), and familiarity with frameworks like MITRE ATT&CK
  • Strong grasp of cloud services (GCP preferred), especially securing data pipelines, model hosting endpoints, and related infrastructure
  • Proficiency with Infrastructure-as-Code (Terraform, Crossplane, or similar) and security scanning for cloud resources
  • Proficiency with scripting and automation (e.g., Python, Bash)
  • The ability to thoughtfully participate in technical discussions and drive towards data-driven decisions amidst ambiguity and competing priorities
  • Strong communication skills and empathy for developer needs, with a demonstrated ability to embed secure practices without creating friction

What Sets You Apart:
  • Experience building or scaling an AppSec or DevSecOps program from early maturity, including establishing paved roads and measuring adoption
  • Familiarity with commercial security platforms such as Orca Security (CNAPP/cloud security posture) and Aikido Security (application security scanning) is a plus
  • Experience securing ML toolchains (e.g., TensorFlow, PyTorch) and familiarity with AI-specific threats such as data leakage, model inversion, prompt injection, and adversarial inputs
  • Hands-on experience integrating and managing Web Application Firewalls (WAF), anti-DDoS systems, and edge protection technologies
  • Familiarity with monitoring and observability systems (e.g., Prometheus, Grafana, OpenTelemetry) with a focus on detecting security anomalies
  • Familiarity with AI governance and compliance standards (e.g., EU AI Act, NIST AI Risk Management Framework)
  • Strong interest in harnessing AI and LLM tools as a force multiplier - using them to code smarter, iterate faster, boosting productivity and enhancing product capabilities


For high cost of living areas (San Francisco Bay, New York City, and Seattle), the expected salary range for this position is $198,000 USD - $233,000 USD, plus bonus eligibility and equity.

For all other US locations, the expected salary range for this position is $172,000 USD - $216,000 USD, plus bonus eligibility and equity.

Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 83% and 100% of range. Please discuss your specific work location with your recruiter for more information.

Censys offers a competitive benefits package to employees, including equity, health, dental & vision coverage, retirement with company contribution, parental leave, mental health & wellness benefits, flexible PTO, and a professional development stipend. Censys also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Censys's compensation and benefits are subject to change and may be modified in the future. Please see our careers page for more details.

To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates to keep their cameras on during video interviews. Additionally, if hired, we would love to bring you to our HQ in Ann Arbor for in-person onboarding.

Our roots are in Ann Arbor, Michigan and our innovation is fueled by the team's global perspectives. For this role, we are open to remote employees across the continental US.

About Censys

Censys is a cybersecurity company that provides internet-wide visibility and real-time threat detection and analysis. The company's platform enables organizations to discover and track devices and assets that are connected to the internet, and identify vulnerabilities and threats that could impact their security. Censys' customers include Fortune 500 companies, government agencies, and security teams around the world. The company was founded in 2013 by a team of researchers from the University of Michigan, and is headquartered in Ann Arbor, Michigan.
Learn more about Censys
Size
50 employees
Industry
Founded
2017

Similar Jobs

More Jobs at Censys

More Information Technology Jobs

Find similar Staff Application Security Engineer jobs: