Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Council on Legal Education Opportunity (CLEO)

Staff Application & Product Security Engineer

Council on Legal Education Opportunity (CLEO)

. Own and mature Cleo’s secure software development lifecycle, including security requirements, threat modeling, and design reviews .

Posted 10/2/2026full-timeRemote • United StatesLead💰 $160,000 - $180,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application and product security, including secure software development lifecycle management, threat modeling, and vulnerability remediation. Proficient in integrating security practices within CI/CD pipelines and collaborating with engineering teams to enhance security posture.

Highest-signal resume keywords
Application SecuritySecure Software EngineeringThreat ModelingSAST IntegrationJava Programming

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Object-Oriented ProgrammingJavaTypeScriptPythonGoAPI SecurityVulnerability RemediationSecurity TestingExploit ReproductionPatch Validation
Soft Skills
CollaborationCommunicationTechnical Risk TranslationRemediation Guidance
Tools & Technologies
GitHubCI/CD PipelinesAWSKubernetesTerraformJenkinsSnykBurp SuiteSemgrep
Certifications & Qualifications
CSSLPOSWEGWAPTAWS Security
Industry Keywords
NIST CSF 2.0OWASP Top 10CVE LifecycleSaaS SecurityRBAC Design

Tech Stack

Tools & technologies
AWSCloudJavaJenkinsKubernetesPythonTerraformTypeScriptGo

About the role

Key responsibilities & impact
  • Own and mature Cleo’s secure software development lifecycle, including security requirements, threat modeling, and design reviews
  • Run and tune SAST, SCA, secrets detection, container, and IaC scanning
  • Build reusable secure patterns, reference implementations, and policy-as-code controls
  • Lead developer security enablement through Security Champions, training, remediation guidance, office hours, and self-service capabilities
  • Run risk-based triage, remediation, verification, SLAs, escalations, and exceptions for application and product vulnerabilities
  • Reproduce externally reported vulnerabilities and validate patches before release
  • Own and coordinate penetration-testing engagements and targeted testing
  • Run the Vulnerability Disclosure Program and coordinate researcher communications and disclosure
  • Coordinate the CVE lifecycle and support product-security incident response
  • Own application and product-security controls in Cleo’s NIST CSF 2.0 program, tracking maturity, closing gaps, and producing audit evidence
  • Own the security posture of SaaS and customer-hosted products, including secure defaults, authentication, session controls, RBAC, tenant isolation, admin data access, configuration, and hardening guidance
  • Own the Product Security Roadmap with Product Management, the CTO, and Architecture
  • Prioritize and ship security features including SSO/SAML upgrades, RBAC redesign, endpoint-level access control, and customer-requested controls
  • Represent security in RTE Sync and Boundary Review
  • Triage customer vulnerability-scan findings and penetration-test reports
  • Answer security RFIs and enhancement requests
  • Author customer-facing advisories, security release notes, and hardening documentation
  • Own threat modeling and security reviews for LLM-enabled features, AI agents, and AI-assisted development workflows
  • Build controls for prompt injection, sensitive data exposure, insecure output handling, excessive agency, insecure tool integrations, and AI supply-chain risk
  • Apply OWASP Top 10 for LLM Applications and NIST AI Risk Management Framework across product and engineering
  • Report to the CISO and partner with Engineering and the Cloud Security team

Requirements

What you’ll need
  • 6+ years in application security, product security, or secure software engineering, including experience building or maturing an AppSec program across multiple engineering teams
  • Strong proficiency in an object-oriented programming language; Java preferred
  • Ability to read, debug, and write production-quality code
  • Comfort working across TypeScript, Python, or Go
  • Deep knowledge of authentication, authorization, API security, business-logic flaws, and modern service architectures
  • Hands-on experience integrating and tuning SAST, SCA, and secrets scanning in GitHub and CI/CD pipelines
  • Hands-on exploit reproduction and patch validation against running Java web applications
  • Coordinated disclosure experience with external security researchers and customers, including driving a CVE to publication
  • Product security experience on shipped software with an installed base
  • Experience running threat modeling, design reviews, and manual security testing
  • Ability to work directly with developers through remediation
  • Ability to translate technical risk into engineering guidance for developers and executives
  • Ability to hold release-gating decisions with Engineering leadership
  • Nice-to-have: securing LLM applications, AI agents, or AI-assisted development tools
  • Nice-to-have: SBOM, CycloneDX/SPDX, VEX, artifact signing, and SLSA
  • Nice-to-have: AWS, Kubernetes/EKS, Terraform, Jenkins
  • Nice-to-have: Snyk, GitHub Advanced Security, Semgrep, Burp Suite
  • Nice-to-have: NIST CSF 2.0, OWASP SAMM/ASVS, NIST SSDF, SOC 2 or ISO 27001 audits
  • Nice-to-have: CSSLP, OSWE, GWAPT, AWS Security, or comparable certifications
  • Nice-to-have: SaaS and customer-hosted deployment models; SSO/SAML, RBAC design, multi-tenant isolation; MFT/EDI or other B2B integration products

Benefits

Comp & perks
  • Bonus Opportunity
  • Great Healthcare + Dental + Vision
  • Flexible PTO
  • Culture of support, encouraging Life-Work balance
  • 401k match
  • FSA and HSA options
  • Employee Assistance Program
  • Paid Parental Leave
  • Remote work environment
  • Accelerated title and salary growth potential
  • Fun and energetic work environment