Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Shield AI

Staff Application Security Engineer

Shield AI

. Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements .

Posted 9/23/2026full-timeRemote • United StatesLead💰 $143,000 - $214,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in secure SDLC policies, application security, and vulnerability management, with a strong focus on integrating security practices into development workflows. Proficient in threat modeling, secure coding, and software supply-chain security, ensuring compliance with industry standards and frameworks.

Highest-signal resume keywords
Secure SDLC ImplementationApplication Security TestingVulnerability ManagementThreat ModelingSoftware Supply-Chain Security

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Secure Coding PracticesApplication-Security ToolingCI/CD IntegrationDependency Vulnerability ManagementSecurity Requirements DefinitionAPI SecurityAuthentication and AuthorizationProduction Code AssessmentOpen-Source Software GovernanceSecurity Design Review
Soft Skills
Strong Written CommunicationStrong Verbal Communication
Tools & Technologies
SASTDASTSCAGitHub Advanced SecurityGitLab Security ToolsOWASP ZAPBurp SuiteSnykCheckmarxVeracode
Certifications & Qualifications
CSSLPCISSPGWAPTGWEBOSWEGIAC
Industry Keywords
NIST SP 800-218OWASP SAMMSLSACMMCFedRAMPISO 27001SOC 2SBOMVEXCycloneDX

Tech Stack

Tools & technologies
CloudCyber SecurityKubernetesMicroservicesSDLC

About the role

Key responsibilities & impact
  • Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements
  • Translate security policy into clear, achievable requirements for development, product, and platform teams
  • Assess maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead improvement roadmaps
  • Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials
  • Partner with development teams to identify, triage, prioritize, remediate, and verify application-security findings
  • Evaluate, implement, tune, and operationalize SAST, DAST, SCA, secrets detection, infrastructure-as-code security scanning, container/image scanning, API, and cloud-native security controls
  • Ensure security tooling produces actionable findings and minimizes false positives
  • Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews
  • Establish risk-based vulnerability management, remediation SLOs, compensating controls, risk acceptance, escalation, and exception management
  • Develop processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies
  • Establish open-source software governance, component inventory, license identification and review, approval workflows, and policy enforcement
  • Mature software supply-chain security practices, including SBOMs, VEX, build and release provenance, artifact/package/container/binary signing, artifact verification, trusted promotion, secure repositories, approved dependency sources, and SLSA-aligned controls
  • Partner with DevOps and platform engineering to secure CI/CD pipelines, source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines
  • Support vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage, and product-security incident response
  • Create and lead a security champions program with secure-coding guidance, training, office hours, practical tools, and timely security engagement
  • Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity
  • Support customer, regulatory, audit, and assurance activities related to secure development and software supply-chain practices

Requirements

What you’ll need
  • 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related field
  • Experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams
  • Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles
  • Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices
  • Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling
  • Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows
  • Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition
  • Knowledge of authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities
  • Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management
  • Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes
  • Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable frameworks
  • Ability to read and assess production code and scripts in one or more modern programming languages
  • Strong written and verbal communication skills
  • Preferred: experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls
  • Preferred: experience with VEX, CSAF, SPDX, CycloneDX, and component or vulnerability intelligence workflows
  • Preferred: experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code
  • Preferred: experience with source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms
  • Preferred: experience with Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies
  • Preferred: experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements
  • Preferred: relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials
  • Offers contingent on a cleared background and possible reference check

Benefits

Comp & perks
  • Bonus
  • Benefits package
  • Equity
  • Temporary benefits package applicable after 60 days of employment (temporary employees)
  • Remote work arrangement
  • Equal employment opportunity and workplace accommodation support