Application Security Engineer
Vannevar $160K–$210K/yr
Defense and Space Manufacturing · 51-200 employees
About the role
You will implement and deploy enterprise-standard security checks like SAST, SCA, and DAST within the CI/CD pipeline. Additionally, you will partner with development teams to conduct threat modeling, review code, and drive a shift-left vulnerability detection program.
What they look for
Requirements
The role requires 5+ years of experience in Application or Product Security with hands-on expertise in securing web applications. Candidates should be proficient in DevSecOps practices, container security, and programming languages such as Python and TypeScript.
Benefits
Full description
Vannevar builds AI systems for the Department of War's most consequential missions. We have 125 deployments across every branch and combatant command spanning our core platform and five distinct products. An an example of how we work, when major combat operations started with Iran, we fielded a new product supporting 24/7 operations and 9,000+ users in three months.
How we build is our advantage: we deploy forward with the people who own the mission. Our engineers, product team, and CTO deploy forward to the point of friction, including visiting units in Ukraine. We focus on embedding directly with operational units supporting great power competition with China, combat operations with Iran, and counter-narcotics missions.
About the role
As an Application Security Engineer, you will help build security into our SaaS platform, ensuring we can quickly ship secure features to our customers. You will partner with software, DevOps, and platform teams, while coordinating with audit partners, to embed threat modeling, automated SAST/SCA/DAST, and rapid vulnerability response into every stage of our SDLC. Your work will be pivotal in protecting customer data, meeting compliance milestones, and scaling our security posture as the company grows.
What you'll do
- Implement and deploy enterprise standard SAST, SCA, secrets-scan, DAST, and container/IaC checks in CI/CD
- Embed with development teams to run threat models, review critical PRs, and coach secure-by-default habits.
- Drive a shift-left vulnerability detection program to identify and remediate vulnerabilities earlier in the software development lifecycle (SDLC).
- Coordinate with DevOps for application security issues that cross between application and infrastructure layers
- Support incident-response for product issues and feed lessons back into code, docs, and process.
What you should have
- 5 + years in Application / Product Security
- Hands-on experience securing web applications and automating AppSec workflows.
- Familiarity with DevSecOps practices and container security & patching
- Experience with GitHub Actions, Python, TypeScript/JavaScript
- Clear, concise communicator who can translate risk for engineers
Nice to have
- Experience securing LLM workflows
- Experience with NIST Risk Management Framework
- Experience with software security at a U.S. defense contractor
- Active Security Clearance (or ability to obtain one) and willingness to travel onsite
Benefits:
- Health, dental, and vision insurance
- 100% remote - work from anywhere in the US
- 401k matching
- Mental benefits
- Flexible work environment - you manage your workday
- Pet and child care reimbursement during travel
- Unlimited PTO
Compensation The salary range for this position is $160,000 - $210,000 + equity + 401K match. Within the range, individual pay is determined by experience, relevant education, and/or training.
Vannevar is an equal opportunity employer, and qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
We encourage candidates from all backgrounds to apply, even if you don't feel like you're a perfect fit. If you're passionate about contributing to our mission, we'd love to hear from you!
IMPORTANT NOTICE We are committed to protecting the privacy of all applicants. Official emails from the company will come from an @vannevarlabs.com domain. Under no circumstances will a legitimate representative from our company contact you to request passwords, financial information, or other sensitive personal data. Please be vigilant of potential scams.
Similar roles
-
Staff Security Engineer
Robots and Pencils United States · $116K–$160K/yr
-
Cybersecurity Awareness Volunteer
CyberUp St. Louis, Missouri, United States
-
Senior Security Engineer
Latitude IT Solutions $119K–$137K/yr
-
Security Engineer
Latitude IT Solutions $102K–$118K/yr
-
2027 Internal Audit - Information Technology & Cybersecurity Summer Internship
Brown Brothers Harriman New York, New York, United States · $52K/yr
-
Security Engineer III - Network and Cloud Security - Hybrid (Remote Considered) - 26-103
PriMed Management Consulting Services, Inc. San Ramon, California, United States · $109K–$144K/yr