<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>aff17a60-097</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>As a Security Engineer focused on Application and Product Security, you will play a key role in improving the security posture of our applications, services, and development ecosystem.</p>
<p>You will work closely with engineering teams to integrate security into the software development lifecycle, build secure-by-default patterns, and ensure that products are resilient against modern threats.</p>
<p>This role combines hands-on technical work, security engineering, and collaboration with developers to guide secure design and remediation.</p>
<p>You will help implement security controls, perform assessments, and contribute to the continuous improvement of our security program.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Integrating application security best practices into the development lifecycle by partnering with engineering teams and enabling automated security checks within CI/CD pipelines.</li>
</ul>
<ul>
<li>Supporting and maintaining Application Security based tooling,including SAST, DAST, SCA, and secrets scanning,and helping developers interpret and remediate findings.</li>
</ul>
<ul>
<li>Conducting secure code reviews, threat modeling sessions, and application architecture assessments to identify risks and propose mitigation strategies.</li>
</ul>
<ul>
<li>Developing and maintaining security automation, guardrails, and reusable components.</li>
</ul>
<ul>
<li>Assisting in defining and improving secure coding standards and application hardening practices.</li>
</ul>
<ul>
<li>Supporting monitoring and detection efforts by helping improve application-level logging, telemetry, and alerting.</li>
</ul>
<ul>
<li>Assisting in incident response activities related to application vulnerabilities, including verification, triage, and remediation support.</li>
</ul>
<ul>
<li>Staying current on emerging threats, vulnerabilities, and best practices in application and product security.</li>
</ul>
<ul>
<li>Contributing to documentation including security requirements, guidelines, and remediation playbooks.</li>
</ul>
<ul>
<li>Participating in internal security reviews, compliance-driven assessments, and architectural walkthroughs.</li>
</ul>
<ul>
<li>Developing and helping maintain existing application security tools, pipelines, and workflows.</li>
</ul>
<ul>
<li>Collaborating with engineering and product teams to ensure secure deployment and continuous improvement of applications.</li>
</ul>
<p>Requirements include:</p>
<ul>
<li>A bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.</li>
</ul>
<ul>
<li>2–5 years of experience in application security, product security, software engineering with a security focus, or a related technical role.</li>
</ul>
<ul>
<li>Strong understanding of application vulnerabilities and mitigation strategies (OWASP Top 10, CWE).</li>
</ul>
<ul>
<li>Experience with CI/CD tooling, Git-based workflows, and modern development practices.</li>
</ul>
<ul>
<li>Familiarity with cloud security concepts and hands-on experience with at least one cloud platform (AWS, Azure, or GCP).</li>
</ul>
<ul>
<li>Experience with one or more programming languages such as Python, Go, Java, JavaScript/Typescript, or Ruby. (Java and Python preferred.)</li>
</ul>
<ul>
<li>Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning.</li>
</ul>
<ul>
<li>Knowledge of secure coding principles, API security, authentication, authorization, and secrets management.</li>
</ul>
<ul>
<li>Strong problem-solving skills and the ability to communicate technical issues clearly to developers and cross-functional stakeholders.</li>
</ul>
<ul>
<li>Understanding of agile development processes and working within engineering teams.</li>
</ul>
<ul>
<li>Ability to Travel: This role will require 25% in-person travel for purposes including but not limited to new hire onboarding, team and department offsites, customer engagements, and other company events.</li>
</ul>
<p>This role is based in our Boston office and follows a hybrid model, with an expectation of being onsite 1-2 days per week.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$130,000-$170,000 USD</Salaryrange>
      <Skills>CI/CD tooling, Git-based workflows, modern development practices, cloud security concepts, application security tools, secure coding principles, API security, authentication, authorization, secrets management, Python, Go, Java, JavaScript/Typescript, Ruby</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Starburst</Employername>
      <Employerlogo>https://logos.yubhub.co/starburst.io.png</Employerlogo>
      <Employerdescription>Starburst is a data platform company that unifies data across clouds and on-premises to accelerate AI innovation.</Employerdescription>
      <Employerwebsite>https://www.starburst.io/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/starburst/jobs/5119301008</Applyto>
      <Location>Boston, MA</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
  </jobs>
</source>