Back to Jobs
Mozilla
Development 1h ago

Application Security Engineer

Mozilla
United StatesUnited States
Full-time
$160,000 - $210,000 + equity + 401K match
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
Python2h 41mFree Trial ✨
Start 10-Day Free Trial
TypeScript/JavaScriptCybersecuritySAST/SCA/DAST

Want to know if you're a match for this job?

Calculate My Match Score

Vannevar is a defense technology company building AI to deter our adversaries. In the 21st century, conflict moves at algorithmic speed and foresight equals firepower. Our agentic AI is purpose-built to compete with China—from cross-Strait conflict to gray zone coercion. Trained on the most mission-relevant datasets in defense, our technology models adversary behavior, simulates campaigns, and recommends the best course of action to decision makers. Our AI systems are some of the most trusted in the industry and actively used on the front lines of the Indo-Pacific to keep the peace and save lives.

Exceptional technology starts with exceptional people. Vannevar is a small agile team combining world-class engineers with veteran strategists who bring deep expertise in defense and tradecraft. We’re building a company defined by mission impact, user empathy, and disciplined growth. In just three years, we grew from $3M to $80M in ARR, achieved early profitability, and reached unicorn status—proving that disruption doesn’t require an ego, and staying power doesn’t mean standing still.

About the role

As an Application Security Engineer, you will help build security into our SaaS platform, ensuring we can quickly ship secure features to our customers. You will partner with software, DevOps, and platform teams, while coordinating with audit partners, to embed threat modeling, automated SAST/SCA/DAST, and rapid vulnerability response into every stage of our SDLC. Your work will be pivotal in protecting customer data, meeting compliance milestones, and scaling our security posture as the company grows.

What you'll do

  • Implement and deploy enterprise standard SAST, SCA, secrets-scan, DAST, and container/IaC checks in CI/CD
  • Embed with development teams to run threat models, review critical PRs, and coach secure-by-default habits.
  • Drive a shift-left vulnerability detection program to identify and remediate vulnerabilities earlier in the software development lifecycle (SDLC).
  • Coordinate with DevOps for application security issues that cross between application and infrastructure layers
  • Support incident-response for product issues and feed lessons back into code, docs, and process.

What you should have

  • 5+ years in Application / Product Security
  • Hands-on experience securing web applications and automating AppSec workflows.
  • Familiarity with DevSecOps practices and container security & patching
  • Experience with GitHub Actions, Python, TypeScript/JavaScript
  • Clear, concise communicator who can translate risk for engineers

Nice to have

  • Experience securing LLM workflows
  • Experience with NIST Risk Management Framework
  • Experience with software security at a U.S. defense contractor
  • Active Security Clearance (or ability to obtain one) and willingness to travel onsite

How would you rate this job post?

See what other professionals think about this role.

banner

Mozilla is a global, grassroots community of people dedicated to making the web open, a global resource for all, and a healthy alternative to the closed, proprietary, and often exploitative web. We are best known for the Firefox web browser. We believe the internet is a public resource, not a commodity to be privately controlled. We are a non-profit organization, and our mission is to ensure the Internet remains a powerful force for good in the world.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Application Security Engineer at Mozilla | HireSkys