Staff/Lead Application Security Engineer

Beacon Software Inc

$150K — $180K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in application security or related fields.
  • Expert knowledge of web and API security concepts.
  • Proven track record of implementing security processes across multiple teams.
  • Experience securing applications in cloud environments and containerized workloads.
  • Strong coding skills to author fixes and automate processes.

Responsibilities

  • Set the strategy and roadmap for product security at Beacon.
  • Lead security architecture reviews and threat modeling for new products.
  • Manage the product security assessment of newly acquired codebases.
  • Conduct secure code reviews focused on complex vulnerabilities.
  • Oversee vulnerability management and remediation processes.
  • Define and integrate security tooling into CI/CD pipelines.
  • Produce secure coding standards and training for engineering teams.

Benefits

  • Opportunity to pioneer the application security program from the ground up.
  • Collaborative environment embedded with engineering teams across various products.
  • Access to cutting-edge challenges, particularly in AI security and threat modeling.
  • Influence and set standards across diverse codebases in a growing company.
  • Opportunity to engage in hands-on coding and automation efforts.
Full Job Description
The role

You will be Beacon's first dedicated application security engineer. You will set the strategy for product security and start to build the program.

Beacon's application security surface spans both Beacon's own engineering and our portfolio companies' products, each independently built with its own stack and engineering team. You will embed with the teams that own the code, whether at Beacon HQ or within a portfolio company, working inside their design reviews and planning, and own the technical roadmap for product security as Beacon grows.

What Application Security owns

This is the full remit of Application Security at Beacon. It is more than one person can cover at once. As the first member of the team, you will stand up the essentials, prioritize the highest-leverage work first, and build the rest into a roadmap.
  • Secure design and architecture: lead threat modeling and security architecture review for new product work and platform initiatives, and define standards for authentication, authorization, encryption, and tenant isolation.
  • Acquisition assessment: own the product security review of newly acquired codebases and cloud environments, establishing baseline posture, material risk, and the remediation path.
  • Code and security review: perform secure code review, targeting authorization and business logic flaws that automated tooling does not catch. Identify and manage the external partner who runs penetration testing against our products and infrastructure, and drive remediation of what they find.
  • AI security: assess AI features across our products, including agent architectures, model and tool access, delegated credentials, and the data reachable through them.
  • Vulnerability management: own the end-to-end program, including intake, severity, prioritization, remediation SLAs, and reporting, and drive fixes through engineering teams in a way they can sustain.
  • Tooling and automation: own the standard for SAST, DAST, SCA, and secrets scanning, and its integration into CI/CD across the portfolio. Build the automation that lets one person cover a multi-team portfolio, including routine fix PRs, dependency remediation, and findings routing. Own the security of any internal tools you build, including their access to credentials, source code, and production systems.
  • Enablement: write the secure coding standards and training that engineering teams consult before they build.
  • Incident response: serve as the product security expert during incidents, from investigation through remediation and postmortem.
  • Compliance partnership: work with GRC to produce the evidence audit and customer security review require, without letting compliance drive the security roadmap.
What we are looking for
  • Would rather build a system that finds every instance of a bug than fix one at a time.
  • Already uses AI as part of how you work, with real opinions on where it helps and where it doesn't, including judgment on when to build tooling versus buy it.
  • Can set architecture and standards across many codebases, not just review one at a time.
  • Ships production code yourself. You should be able to author a fix, not only specify it.
  • Expert knowledge of web and API security, identity and access design (authentication, authorization, RBAC/ABAC), and applied cryptography.
  • Experience securing applications in cloud environments and containerized workloads.
  • A track record of driving security work to completion in engineering organizations outside your reporting line.


Similar Jobs

More Jobs at Beacon Software Inc

  • Strategic Finance Director
    $150K — $180K *
    Toronto, ON M3C 0E3
    Finance & Insurance
    In-Person
  • Product Counsel
    $150K — $180K *
    New York, NY 10025 (New York County)
    Legal & Accounting
    In-Person
  • Product Counsel
    $150K — $180K *
    San Francisco, CA 94112 (San Francisco County)
    Legal & Accounting
    In-Person
  • Employment Counsel
    $110K — $130K *
    Toronto, ON M3C 0E3
    Legal & Accounting
    In-Person
  • Privacy Counsel
    $150K — $180K *
    New York, NY 10025 (New York County)
    Legal & Accounting
    In-Person

More Information Technology Jobs

Find similar Staff/Lead Application Security Engineer jobs: