{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/title/application-security-engineer"},"x-facet":{"type":"title","slug":"application-security-engineer","display":"Application Security Engineer","count":8},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b5d99aa9-e84"},"title":"Application Security Engineer","description":"<p>As an Application Security Engineer at Palantir, you will be hands-on and have wide-ranging impact for the security of Palantir. Key responsibilities include:</p>\n<p>Performing deep architecture and security reviews on highly complex products to identify vulnerabilities Leading engineering teams in feature design, threat modeling, and security-critical code and architecture Developing and implementing automation to eliminate entire classes of weaknesses across the organisation Driving decision-making by determining the trade-offs between security and product design Leading implementation of strategic security initiatives that improve security across Palantir</p>\n<p>We value self-motivated individuals with experience in solving complex problems, strong communication and collaboration skills, and the ability to learn and apply new technologies quickly.</p>\n<p>Experience with modern high-level programming languages, such as Java, Golang, JavaScript, or Python, is essential. Demonstrated experience evaluating code for vulnerabilities and weaknesses, as well as experience with complex architectures and codebases, is also required.</p>\n<p>The estimated salary range for this position is $135,000 - $200,000 per year, with total compensation including Restricted Stock units, sign-on bonus, and other potential future incentives.</p>\n<p>Benefits include employees&#39; eligibility for medical, dental, and vision insurance, as well as voluntary life insurance. Commuter benefits, relocation assistance, and paid time off are also provided.</p>\n<p>At Palantir, we want every employee to achieve their best outcomes, and we celebrate individuals&#39; strengths, skills, and interests. We promote health and well-being across all areas of employees&#39; lives and invest in our community.</p>\n<p>If you want to empower the world&#39;s most important institutions, you belong here. Palantir values excellence regardless of background and is proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b5d99aa9-e84","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Palantir","sameAs":"https://www.palantir.com/","logo":"https://logos.yubhub.co/palantir.com.png"},"x-apply-url":"https://jobs.lever.co/palantir/a5fdd5ec-d1f3-4837-83af-161b003931dd?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$135,000 - $200,000 per year","x-skills-required":["Java","Golang","JavaScript","Python","CodeQL","Static code analysis"],"x-skills-preferred":[],"datePosted":"2026-04-25T20:34:28.854Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington, D.C."}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Java, Golang, JavaScript, Python, CodeQL, Static code analysis","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":135000,"maxValue":200000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_a691a2ea-fc1"},"title":"Application Security Engineer","description":"<p>A World-Changing Company</p>\n<p>Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.</p>\n<p>The Role</p>\n<p>Our products support some of the most important and impactful work in the world, including defence, intelligence, and commercial applications. We are trusted by our customers to protect their mission-critical information in the face of advanced persistent threats.</p>\n<p>As an Application Security Engineer, you will be hands-on and have wide-ranging impact for the security of Palantir:</p>\n<ul>\n<li>Product security reviews. You will perform full-scope security reviews of our current and future product and service portfolio. This includes whitebox, greybox, and blackbox assessments. You will work with offensive security teams, engineering teams, and other members of the InfoSec organisation to harden our products against our dedicated adversaries.</li>\n</ul>\n<ul>\n<li>Architecture and design. You will be the security subject matter expert for product architects and engineers. You will threat model, assess risks, and help implement security controls and mitigations to address identified issues. You will directly steer the design of our products to ensure we are secure-by-default.</li>\n</ul>\n<ul>\n<li>Strategic security initiatives. You will be empowered to own transformational security initiatives that impact the whole company. Members of the Application Security Team have implemented software supply chain security controls (e.g., in-toto), implemented hardware-backed GPG key signing for commits, developed new security services, implemented security automation, or worked on massive-scale security problems.</li>\n</ul>\n<ul>\n<li>Vulnerability identification and analysis. You will be responsible for finding new and novel ways to identify and resolve security vulnerabilities in our products. This includes static and dynamic code analysis, security scanning, investigation of security reports from InfoSec, our bug bounty programme, or other trusted partners, and direct work with our incident response team on product security issues and incidents.</li>\n</ul>\n<p>This role has wide-reaching impact, strong autonomy, and the resources and empowerment to make significant security improvements across all Palantir.</p>\n<p><strong>Core Responsibilities</strong></p>\n<ul>\n<li>Perform deep architecture and security reviews on highly complex products to identify vulnerabilities</li>\n</ul>\n<ul>\n<li>Lead engineering teams in feature design, threat modelling, and security-critical code and architecture</li>\n</ul>\n<ul>\n<li>Develop and implement automation to eliminate entire classes of weaknesses across the organisation</li>\n</ul>\n<ul>\n<li>Drive decision-making by determining the trade-offs between security and product design</li>\n</ul>\n<ul>\n<li>Lead implementation of strategic security initiatives that improve security across Palantir</li>\n</ul>\n<p><strong>What We Value</strong></p>\n<ul>\n<li>Self-motivated, experience in solving complex problems</li>\n</ul>\n<ul>\n<li>History and experience designing and shipping production-ready software</li>\n</ul>\n<ul>\n<li>Strong communication and collaboration skills who feels comfortable working closely with engineering teams</li>\n</ul>\n<ul>\n<li>Ability to learn and apply new technologies quickly and in complex deployments</li>\n</ul>\n<p><strong>What We Require</strong></p>\n<ul>\n<li>Development or software engineering experience and a deep passion for information security</li>\n</ul>\n<ul>\n<li>Experience with a modern high-level programming language (e.g. Java, Golang, Javascript, Python, etc.)</li>\n</ul>\n<ul>\n<li>Demonstrated experience evaluating code for vulnerabilities and weaknesses</li>\n</ul>\n<ul>\n<li>Experience with complex architectures and codebases (e.g. SOA or micro-services)</li>\n</ul>\n<ul>\n<li>Experience utilising/with CodeQL or other static code analysis platforms</li>\n</ul>\n<ul>\n<li>Experience performing black-box testing of web applications</li>\n</ul>\n<p><strong>Additional Information</strong></p>\n<p>The estimated salary range for this position is estimated to be $135,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individual’s relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.</p>\n<p>Our benefits aim to promote health and wellbeing across all areas of Palantirians’ lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies.</p>\n<p>Benefits</p>\n<ul>\n<li>Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance</li>\n</ul>\n<ul>\n<li>Employees are automatically covered by Palantir’s basic life, AD&amp;D and disability insurance</li>\n</ul>\n<ul>\n<li>Commuter benefits</li>\n</ul>\n<ul>\n<li>Relocation assistance</li>\n</ul>\n<ul>\n<li>Take what you need paid time off, not accrual based</li>\n</ul>\n<ul>\n<li>2 weeks paid time off built into the end of each year (subject to team and business needs)</li>\n</ul>\n<ul>\n<li>10 paid holidays throughout the calendar year</li>\n</ul>\n<ul>\n<li>Supportive leave of absence program including time off for military service and medical events</li>\n</ul>\n<ul>\n<li>Paid leave for new parents and subsidised back-up care for all parents</li>\n</ul>\n<ul>\n<li>Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation</li>\n</ul>\n<ul>\n<li>Stipend to help with expenses that come with a new child</li>\n</ul>\n<ul>\n<li>Employees can enroll in Palantir’s 401k plan</li>\n</ul>\n<p>Life at Palantir</p>\n<p>We want every Palantirian to achieve their best outcomes, that’s why we celebrate individuals’ strengths, skills, and interests, from your first interview to your long-term growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimise our opportunities to grow and helps ensure many pathways to success at Palantir.</p>\n<p>Promoting health and wellbeing across all areas of Palantirians’ lives is just one of the ways we’re investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region.</p>\n<p>In keeping consistent with Palantir’s values and culture, we believe employees are “better together” and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for “Remote” work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_a691a2ea-fc1","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Palantir","sameAs":"https://www.palantir.com/","logo":"https://logos.yubhub.co/palantir.com.png"},"x-apply-url":"https://jobs.lever.co/palantir/7e3ec54c-b73a-4014-8ef3-cdce8a4953c4?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$135,000 - $200,000/year","x-skills-required":["Java","Golang","Javascript","Python","CodeQL","static code analysis platforms","black-box testing of web applications"],"x-skills-preferred":[],"datePosted":"2026-04-25T20:33:51.657Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Java, Golang, Javascript, Python, CodeQL, static code analysis platforms, black-box testing of web applications","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":135000,"maxValue":200000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_da074832-80f"},"title":"Application Security Engineer","description":"<p>A World-Changing Company</p>\n<p>Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.</p>\n<p>Our Product Security team works on secure-by-design and deep product partnership. We build strong relationships with other teams and help them build secure software. This includes reviewing early-stage designs, helping develop threat models.</p>\n<p>The Role</p>\n<p>Our products support some of the most important and impactful work in the world, including defense, intelligence, and commercial applications. We are trusted by our customers to protect their mission-critical information in the face of advanced persistent threats.</p>\n<p>The mission of the Application Security Team is to enable developers to be highly productive, agile, and produce the most secure software possible. Given the mission critical work that Palantir does, investments in application security have never been more important.</p>\n<p>As an Application Security Engineer, you will be hands-on and have wide-ranging impact for the security of Palantir:</p>\n<ul>\n<li>Product security reviews. You will perform full-scope security reviews of our current and future product and service portfolio. This includes whitebox, greybox, and blackbox assessments. You will work with offensive security teams, engineering teams, and other members of the InfoSec organization to harden our products against our dedicated adversaries.</li>\n</ul>\n<ul>\n<li>Architecture and design. You will be the security subject matter expert for product architects and engineers. You will threat model, assess risks, and help implement security controls and mitigations to address identified issues. You will directly steer the design of our products to ensure we are secure-by-default.</li>\n</ul>\n<ul>\n<li>Strategic security initiatives. You will be empowered to own transformational security initiatives that impact the whole company. Members of the Application Security Team have implemented software supply chain security controls (e.g., in-toto), implemented hardware-backed GPG key signing for commits, developed new security services, implemented security automation, or worked on massive-scale security problems.</li>\n</ul>\n<ul>\n<li>Vulnerability identification and analysis. You will be responsible for finding new and novel ways to identify and resolve security vulnerabilities in our products. This includes static and dynamic code analysis, security scanning, investigation of security reports from InfoSec, our bug bounty program, or other trusted partners, and direct work with our incident response team on product security issues and incidents.</li>\n</ul>\n<p>This role has wide-reaching impact, strong autonomy, and the resources and empowerment to make significant security improvements across all Palantir.</p>\n<p>The skills and background of successful candidates may vary highly, but curiosity, tenacity, and a drive to be a world-class security engineer are the underpinnings of our team.</p>\n<p><strong>Core Responsibilities</strong></p>\n<ul>\n<li>Perform deep architecture and security reviews on highly complex products to identify vulnerabilities</li>\n</ul>\n<ul>\n<li>Lead engineering teams in feature design, threat modeling, and security-critical code and architecture</li>\n</ul>\n<ul>\n<li>Develop and implement automation to eliminate entire classes of weaknesses across the organization</li>\n</ul>\n<ul>\n<li>Drive decision-making by determining the tradeoffs between security and product design</li>\n</ul>\n<ul>\n<li>Lead implementation of strategic security initiatives that improve security across Palantir</li>\n</ul>\n<p><strong>What We Value</strong></p>\n<ul>\n<li>Self motivated, experience in solving complex problems</li>\n</ul>\n<ul>\n<li>History and experience designing and shipping production-ready software</li>\n</ul>\n<ul>\n<li>Strong communication and collaboration skills who feels comfortable working closely with engineering teams</li>\n</ul>\n<ul>\n<li>Ability to learn and apply new technologies quickly and in complex deployments</li>\n</ul>\n<p><strong>What We Require</strong></p>\n<ul>\n<li>Development or software engineering experience and a deep passion for information security</li>\n</ul>\n<ul>\n<li>Experience with a modern high-level programming language (e.g. Java, Golang, Javascript, Python, etc.)</li>\n</ul>\n<ul>\n<li>Demonstrated experience evaluating code for vulnerabilities and weaknesses</li>\n</ul>\n<ul>\n<li>Experience with complex architectures and codebases (e.g. SOA or micro-services)</li>\n</ul>\n<ul>\n<li>Experience utilizing/with CodeQL or other static code analysis platforms</li>\n</ul>\n<ul>\n<li>Experience performing black-box testing of web applications</li>\n</ul>\n<p><strong>Additional Information</strong></p>\n<p>Life at Palantir</p>\n<p>We want every Palantirian to achieve their best outcomes, that’s why we celebrate individuals’ strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians’ lives is just one of the ways we’re investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region.</p>\n<p>In keeping consistent with Palantir’s values and culture, we believe employees are “better together” and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for “Remote” work on an exceptional basis. If you are applying for one of these roles, you must work from the city and or country in which you are employed. If the posting is specified as Onsite, you are required to work from an office. If you want to empower the world&#39;s most important institutions, you belong here. Palantir values excellence regardless of background. We are committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_da074832-80f","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Palantir","sameAs":"https://www.palantir.com/","logo":"https://logos.yubhub.co/palantir.com.png"},"x-apply-url":"https://jobs.lever.co/palantir/205c3184-4272-41a9-a1e2-5352d4d00910?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Java","Golang","Javascript","Python","CodeQL","static code analysis platforms","black-box testing of web applications"],"x-skills-preferred":[],"datePosted":"2026-04-25T20:33:34.951Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Java, Golang, Javascript, Python, CodeQL, static code analysis platforms, black-box testing of web applications"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_aff17a60-097"},"title":"Application Security Engineer","description":"<p>As a Security Engineer focused on Application and Product Security, you will play a key role in improving the security posture of our applications, services, and development ecosystem.</p>\n<p>You will work closely with engineering teams to integrate security into the software development lifecycle, build secure-by-default patterns, and ensure that products are resilient against modern threats.</p>\n<p>This role combines hands-on technical work, security engineering, and collaboration with developers to guide secure design and remediation.</p>\n<p>You will help implement security controls, perform assessments, and contribute to the continuous improvement of our security program.</p>\n<p>Key responsibilities include:</p>\n<ul>\n<li>Integrating application security best practices into the development lifecycle by partnering with engineering teams and enabling automated security checks within CI/CD pipelines.</li>\n</ul>\n<ul>\n<li>Supporting and maintaining Application Security based tooling,including SAST, DAST, SCA, and secrets scanning,and helping developers interpret and remediate findings.</li>\n</ul>\n<ul>\n<li>Conducting secure code reviews, threat modeling sessions, and application architecture assessments to identify risks and propose mitigation strategies.</li>\n</ul>\n<ul>\n<li>Developing and maintaining security automation, guardrails, and reusable components.</li>\n</ul>\n<ul>\n<li>Assisting in defining and improving secure coding standards and application hardening practices.</li>\n</ul>\n<ul>\n<li>Supporting monitoring and detection efforts by helping improve application-level logging, telemetry, and alerting.</li>\n</ul>\n<ul>\n<li>Assisting in incident response activities related to application vulnerabilities, including verification, triage, and remediation support.</li>\n</ul>\n<ul>\n<li>Staying current on emerging threats, vulnerabilities, and best practices in application and product security.</li>\n</ul>\n<ul>\n<li>Contributing to documentation including security requirements, guidelines, and remediation playbooks.</li>\n</ul>\n<ul>\n<li>Participating in internal security reviews, compliance-driven assessments, and architectural walkthroughs.</li>\n</ul>\n<ul>\n<li>Developing and helping maintain existing application security tools, pipelines, and workflows.</li>\n</ul>\n<ul>\n<li>Collaborating with engineering and product teams to ensure secure deployment and continuous improvement of applications.</li>\n</ul>\n<p>Requirements include:</p>\n<ul>\n<li>A bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.</li>\n</ul>\n<ul>\n<li>2–5 years of experience in application security, product security, software engineering with a security focus, or a related technical role.</li>\n</ul>\n<ul>\n<li>Strong understanding of application vulnerabilities and mitigation strategies (OWASP Top 10, CWE).</li>\n</ul>\n<ul>\n<li>Experience with CI/CD tooling, Git-based workflows, and modern development practices.</li>\n</ul>\n<ul>\n<li>Familiarity with cloud security concepts and hands-on experience with at least one cloud platform (AWS, Azure, or GCP).</li>\n</ul>\n<ul>\n<li>Experience with one or more programming languages such as Python, Go, Java, JavaScript/Typescript, or Ruby. (Java and Python preferred.)</li>\n</ul>\n<ul>\n<li>Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning.</li>\n</ul>\n<ul>\n<li>Knowledge of secure coding principles, API security, authentication, authorization, and secrets management.</li>\n</ul>\n<ul>\n<li>Strong problem-solving skills and the ability to communicate technical issues clearly to developers and cross-functional stakeholders.</li>\n</ul>\n<ul>\n<li>Understanding of agile development processes and working within engineering teams.</li>\n</ul>\n<ul>\n<li>Ability to Travel: This role will require 25% in-person travel for purposes including but not limited to new hire onboarding, team and department offsites, customer engagements, and other company events.</li>\n</ul>\n<p>This role is based in our Boston office and follows a hybrid model, with an expectation of being onsite 1-2 days per week.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_aff17a60-097","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Starburst","sameAs":"https://www.starburst.io/","logo":"https://logos.yubhub.co/starburst.io.png"},"x-apply-url":"https://job-boards.greenhouse.io/starburst/jobs/5119301008?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"hybrid","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$130,000-$170,000 USD","x-skills-required":["CI/CD tooling","Git-based workflows","modern development practices","cloud security concepts","application security tools","secure coding principles","API security","authentication","authorization","secrets management"],"x-skills-preferred":["Python","Go","Java","JavaScript/Typescript","Ruby"],"datePosted":"2026-04-18T15:51:05.628Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Boston, MA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"CI/CD tooling, Git-based workflows, modern development practices, cloud security concepts, application security tools, secure coding principles, API security, authentication, authorization, secrets management, Python, Go, Java, JavaScript/Typescript, Ruby","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":130000,"maxValue":170000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_8bf116df-95e"},"title":"Application Security Engineer","description":"<p>Job Title: Application Security Engineer</p>\n<p>About the Role: The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. As an Application Security Engineer, you will partner closely with software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>\n<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>\n<li>Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities</li>\n<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>\n<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>\n<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>\n<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>\n<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>\n</ul>\n<p>Requirements:</p>\n<ul>\n<li>5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>\n<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>\n<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>\n<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>\n<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>\n<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>\n<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>\n<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>\n<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>\n<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>\n<li>Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>\n</ul>\n<p>Preferred Qualifications:</p>\n<ul>\n<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>\n<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>\n<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>\n<li>Experience building security tools, applications, and automated tools</li>\n<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>\n<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>\n<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>\n</ul>\n<p>Annual Compensation Range:</p>\n<p>$300,000-$405,000 USD</p>\n<p>Logistics:</p>\n<ul>\n<li>Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience</li>\n<li>Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience</li>\n<li>Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position</li>\n<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>\n<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>\n</ul>\n<p>How to Apply:</p>\n<p>If you&#39;re interested in this role, please submit your application through our website. We look forward to reviewing your application!</p>\n<p>Note:</p>\n<p>Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you&#39;re ever unsure about a communication, don&#39;t click any links,visit anthropic.com/careers directly for confirmed position openings.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_8bf116df-95e","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.com/","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/4502508008?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$300,000-$405,000 USD","x-skills-required":["application security","infrastructure security","cloud-based security","containerized environments","programming languages","Python","Rust","Go","Java","threat modeling","secure design reviews","vulnerability management","bug bounty program","security policies","standards","playbooks","security awareness training"],"x-skills-preferred":["hands-on technical expertise","complex cloud environments","microservices architectures","Kubernetes","Docker","AWS","GCP","offensive security techniques","vulnerability testing","pen testing","red team exercises","AI/ML security risks","prompt injection","data poisoning","model extraction","security tools","applications","automated tools","software engineering principles","communication skills"],"datePosted":"2026-04-18T15:35:09.635Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, infrastructure security, cloud-based security, containerized environments, programming languages, Python, Rust, Go, Java, threat modeling, secure design reviews, vulnerability management, bug bounty program, security policies, standards, playbooks, security awareness training, hands-on technical expertise, complex cloud environments, microservices architectures, Kubernetes, Docker, AWS, GCP, offensive security techniques, vulnerability testing, pen testing, red team exercises, AI/ML security risks, prompt injection, data poisoning, model extraction, security tools, applications, automated tools, software engineering principles, communication skills","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":300000,"maxValue":405000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_6d2bed6a-1bd"},"title":"Application Security Engineer","description":"<p>We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies.</p>\n<p>Responsibilities: Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in our applications Design and implement secure coding guidelines and best practices for development teams Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline Perform threat modeling and risk assessments for applications, developing mitigation strategies for potential risks Manage vulnerability tracking and remediation efforts, providing guidance to development teams Support incident response activities related to application security Stay current on emerging security threats and trends in cloud-native technologies and AI, continuously enhancing our security measures Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs) Address security concerns specific to AI and machine learning models, with a focus on the OWASP LLM Top 10</p>\n<p>Basic Qualifications: Bachelor&#39;s degree in Computer Science, Cybersecurity, or a related field 3-5 years of experience in application security, with a strong focus on code security practices Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10) Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages Experience securing CI/CD pipelines and implementing DevSecOps practices Familiarity with software supply chain security and SBOM generation tools Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10 Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences</p>\n<p>Preferred Skills and Experience: Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features Relevant security certifications (e.g., CSSLP, OSWE) Background in data privacy and compliance regulations relevant to cloud-native applications and AI systems Experience with GitOps and infrastructure-as-code security Familiarity with federated learning and privacy-preserving machine learning techniques Experience in building custom security tooling to enhance and automate security processes Interest in leveraging AI to automate security tasks and improve efficiency Contributions to open-source security projects or tools Experience in securing AI/ML models and data pipelines</p>\n<p>Compensation and Benefits: $200,000 - $340,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_6d2bed6a-1bd","directApply":true,"hiringOrganization":{"@type":"Organization","name":"xAI","sameAs":"https://www.xai.com/","logo":"https://logos.yubhub.co/xai.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/xai/jobs/4559147007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"onsite","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$200,000 - $340,000 USD","x-skills-required":["Python","Rust","Secure coding practices","Application security frameworks","Common vulnerabilities","OWASP Top 10","CI/CD pipelines","DevSecOps practices","Software supply chain security","SBOM generation tools","Security testing tools","Static/dynamic code analysis","AI/ML security implications","OWASP LLM Top 10"],"x-skills-preferred":["Cloud platforms","Security certifications","Data privacy and compliance regulations","GitOps","Infrastructure-as-code security","Federated learning","Privacy-preserving machine learning techniques","Custom security tooling","AI automation","Open-source security projects","AI/ML model security"],"datePosted":"2026-04-18T15:23:13.995Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Rust, Secure coding practices, Application security frameworks, Common vulnerabilities, OWASP Top 10, CI/CD pipelines, DevSecOps practices, Software supply chain security, SBOM generation tools, Security testing tools, Static/dynamic code analysis, AI/ML security implications, OWASP LLM Top 10, Cloud platforms, Security certifications, Data privacy and compliance regulations, GitOps, Infrastructure-as-code security, Federated learning, Privacy-preserving machine learning techniques, Custom security tooling, AI automation, Open-source security projects, AI/ML model security","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":200000,"maxValue":340000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_9eb58719-bef"},"title":"Application Security Engineer","description":"<p><strong>About the role:</strong></p>\n<p>The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. In this hands-on technical role, you will partner closely with software engineers and researchers to ensure security is a core consideration from initial design through implementation.</p>\n<p>You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>\n<p>Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You&#39;ll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions.</p>\n<p><strong>Responsibilities:</strong></p>\n<ul>\n<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>\n<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>\n<li>Conduct secure design reviews and threat modeling. Identify and prioritise risks, attack surfaces, and vulnerabilities</li>\n<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>\n<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritise vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>\n<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>\n<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>\n<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>\n</ul>\n<p><strong>You may be a good fit if you:</strong></p>\n<ul>\n<li>Have 5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>\n<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>\n<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>\n<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>\n<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>\n<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>\n<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>\n<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>\n<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>\n<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>\n<li>Advocate for security fundamentals like least privilege, defence-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>\n</ul>\n<p><strong>Strong candidates may also:</strong></p>\n<ul>\n<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>\n<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>\n<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>\n<li>Experience building security tools, applications, and automated tools</li>\n<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>\n<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>\n<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>\n</ul>\n<p>The annual compensation range for this role is $300,000 - $405,000 USD.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_9eb58719-bef","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://job-boards.greenhouse.io","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/4502508008?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$300,000 - $405,000 USD","x-skills-required":["application security","infrastructure security","cloud security","containerized environments","secure coding practices","vulnerability management","bug bounty program","offensive security","modern application stacks","security tools"],"x-skills-preferred":["Kubernetes","Docker","AWS","GCP","Python","Rust","Go","Java","vulnerability testing","pen testing","red team exercises","AI/ML security risks","security tools","automated tools"],"datePosted":"2026-03-08T13:57:18.711Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA, Seattle, WA, New York City, NY"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, infrastructure security, cloud security, containerized environments, secure coding practices, vulnerability management, bug bounty program, offensive security, modern application stacks, security tools, Kubernetes, Docker, AWS, GCP, Python, Rust, Go, Java, vulnerability testing, pen testing, red team exercises, AI/ML security risks, security tools, automated tools","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":300000,"maxValue":405000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ecb85b57-81f"},"title":"Application Security Engineer","description":"","url":"https://yubhub.co/jobs/job_ecb85b57-81f","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Unknown"},"x-apply-url":"https://job-boards.greenhouse.io/xai/jobs/4559147007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":null,"x-experience-level":null,"x-job-type":null,"x-salary-range":null,"x-skills-required":[],"x-skills-preferred":[]}]}