Senior Application Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
We're hiring a Senior Application Security Engineer to own the security of the software we build. You'll partner closely with engineering to embed security into the Software Development Lifecycle (SDLC), keep our dependencies and supply chain safe, and make sure the product our customers trust is built on a secure foundation. You’ll also have the chance to influence our product, as an internal SME and early security user, your feedback loop directly shapes what we ship.
What You’ll Do
- Embed security into the software development lifecycle: threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt
- Own application security testing - code review, SAST/DAST, and triage - and drive issues to remediation rather than just filing them
- Harden our software supply chain: dependency verification, safe dependency management, and CI/CD pipeline security
- Build and automate security tooling and guardrails so security scales with engineering, not against it
- Serve as the internal security SME on product and workflow decisions, and as an early user of what we build
- Partner across all teams on architecture and design so security is a default, not an afterthought
What We're Looking For
- 5+ years of extensive security engineering experience within product / application security, upholding the highest Trust standards
- Strong hands-on engineer who ships - you produce and automate, you don't just manage process
- Strong software engineering skills; comfortable working in code across the stack (e.g. Python, Go, Typescript, and/or similar)
- Depth in application/product security: secure SDLC, threat modeling, code scanning, and supply-chain / dependency security
- Fluency with the modern AI landscape and how it’s influencing the security picture - staying up to date with the rapidly changing environment
- Able to flex up and down: strategic when it matters, in the weeds when it counts
- Comfortable being an early security hire at a startup - high ownership, ambiguity, and direct impact
Bonus Points
- Experience securing AI/ML products or agentic systems
- Background contributing to developer-enablement or security-champions programs
- Prior experience as an early security hire or building an AppSec function from scratch
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Cloud / DevOps Engineer (Infra & IaC)
Weekday
United StatesSoftware Development Agencies and Engineers for AI Training Code Licensing
Gramian Consulting Group
Australia
CanadaContract Senior Staff Product Manager
Cobalt
United StatesQA Engineer
Nimblegravity
United StatesMore Openings at Cogent Security
Explore Top Companies in this Space
Andesite AI
Cybersecurity / AI / Enterprise Software / SaaS
Dropzone AI
Cybersecurity / Autonomous AI / Security Operations (SOC) / Enterprise Software
IntegrityM
Business Consulting / Compliance / Fraud Detection / Government Services
Open
AI / Customer Support / SaaS / Enterprise Software
Cogent Security
View Company ProfileCogent Security (operating at cogent.security) is an applied AI lab building AI systems for enterprise cybersecurity teams. Founded in 2024 by unknown founders and headquartered in San Francisco, CA, USA, Cogent Security focuses on cybersecurity because it affects everyone—the reliability of critical infrastructure, the integrity of data, and the safety of people. Under the hood, Cogent's AI agents investigate and resolve vulnerabilities at machine speed before attackers exploit them. This allows enterprise cybersecurity teams to reduce the gap between identified risk and risk reduced. Backed by $42 million in Series A funding led by Bain Capital Ventures.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.