<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>f77c41bb-0ad</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert, you will have direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise.</p>
<p>The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm’s information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</li>
<li>Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).</li>
<li>Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.</li>
<li>Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.</li>
<li>Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.</li>
<li>Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.</li>
<li>Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.</li>
</ul>
<p><strong>Qualifications</strong></p>
<ul>
<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field.</li>
<li>5+ years’ experience working as an Application Security Engineer, Software Engineer, or similar role.</li>
<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.</li>
<li>Experience working with AI models, Agentic frameworks and security risks associated with AI.</li>
<li>Experience in working with global teams, collaborating on code and presentations.</li>
<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>
<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.</li>
<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>
<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions.</li>
<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>
<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar.</li>
<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>
<li>Familiarity with web application security testing tools and methodologies.</li>
<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>
<li>Knowledge of Linux, OS internals and containers is a plus.</li>
<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Automated security testing, CI/CD pipelines, Security architectures, Secure configuration principles, Cryptography fundamentals, Encryption protocols, SCM &amp; CI/CD technologies, Security scanning, Vulnerability management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets management, Password vault technologies, Secure programming, Infrastructure as Code tools, Web application security testing tools, Methodologies, Security frameworks, Standards, Linux, OS internals, Containers</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>IT Infrastructure</Employername>
      <Employerlogo>https://logos.yubhub.co/mlp.eightfold.ai.png</Employerlogo>
      <Employerdescription>IT Infrastructure is a technology-focused organisation that provides infrastructure services to various businesses.</Employerdescription>
      <Employerwebsite>https://mlp.eightfold.ai</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://mlp.eightfold.ai/careers/job/755955629927</Applyto>
      <Location>Dublin, Ireland</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>6a75ea8b-5b4</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies, you will play a key role in building toolsets and processes to drive adoption of secure practices across the enterprise.</p>
<p>The successful candidate will have a proven understanding in enterprise security and AI security and will focus on defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks</li>
<li>Conducting specialized threat modeling, red teaming, and risk assessments for AI/ML models</li>
<li>Leading risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects</li>
<li>Engaging throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards</li>
<li>Evangelizing AppSec and AI security best practices through developer education, training materials, and outreach</li>
</ul>
<p>Qualifications include:</p>
<ul>
<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field</li>
<li>5+ years&#39; experience working as an Application Security Engineer, Software Engineer, or similar role</li>
<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs</li>
<li>Experience working with AI models, Agentic frameworks and security risks associated with AI</li>
<li>Experience in working with global teams, collaborating on code and presentations</li>
</ul>
<p>Preferred qualifications include:</p>
<ul>
<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>
<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols</li>
<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>
<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions</li>
<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>
<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar</li>
<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>
<li>Familiarity with web application security testing tools and methodologies</li>
<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>
<li>Knowledge of Linux, OS internals and containers is a plus</li>
<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous</li>
</ul>
<p>We offer a competitive salary and benefits package, as well as opportunities for professional growth and development.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Developer education, Training materials, Outreach, Common SCM &amp; CI/CD technologies, GitHub, Jenkins, Artifactory, Security Scanning, Vulnerability Management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets Management &amp; Password Vault technologies, Delinea Secret Server, Hashicorp Vault, Secure programming, Python, Java, C++, C#, Infrastructure as Code tools, CloudFormation, Terraform, Ansible, Web application security testing tools, Methodologies, Security frameworks, Standards, ISO 27001, NIST, OWASP, Linux, OS internals, Containers</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>IT Infrastructure</Employername>
      <Employerlogo>https://logos.yubhub.co/mlp.eightfold.ai.png</Employerlogo>
      <Employerdescription>IT Infrastructure is a department within a larger organisation that focuses on providing and maintaining the underlying technology infrastructure.</Employerdescription>
      <Employerwebsite>https://mlp.eightfold.ai</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://mlp.eightfold.ai/careers/job/755955629908</Applyto>
      <Location>London, United Kingdom</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>aff17a60-097</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>As a Security Engineer focused on Application and Product Security, you will play a key role in improving the security posture of our applications, services, and development ecosystem.</p>
<p>You will work closely with engineering teams to integrate security into the software development lifecycle, build secure-by-default patterns, and ensure that products are resilient against modern threats.</p>
<p>This role combines hands-on technical work, security engineering, and collaboration with developers to guide secure design and remediation.</p>
<p>You will help implement security controls, perform assessments, and contribute to the continuous improvement of our security program.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Integrating application security best practices into the development lifecycle by partnering with engineering teams and enabling automated security checks within CI/CD pipelines.</li>
</ul>
<ul>
<li>Supporting and maintaining Application Security based tooling,including SAST, DAST, SCA, and secrets scanning,and helping developers interpret and remediate findings.</li>
</ul>
<ul>
<li>Conducting secure code reviews, threat modeling sessions, and application architecture assessments to identify risks and propose mitigation strategies.</li>
</ul>
<ul>
<li>Developing and maintaining security automation, guardrails, and reusable components.</li>
</ul>
<ul>
<li>Assisting in defining and improving secure coding standards and application hardening practices.</li>
</ul>
<ul>
<li>Supporting monitoring and detection efforts by helping improve application-level logging, telemetry, and alerting.</li>
</ul>
<ul>
<li>Assisting in incident response activities related to application vulnerabilities, including verification, triage, and remediation support.</li>
</ul>
<ul>
<li>Staying current on emerging threats, vulnerabilities, and best practices in application and product security.</li>
</ul>
<ul>
<li>Contributing to documentation including security requirements, guidelines, and remediation playbooks.</li>
</ul>
<ul>
<li>Participating in internal security reviews, compliance-driven assessments, and architectural walkthroughs.</li>
</ul>
<ul>
<li>Developing and helping maintain existing application security tools, pipelines, and workflows.</li>
</ul>
<ul>
<li>Collaborating with engineering and product teams to ensure secure deployment and continuous improvement of applications.</li>
</ul>
<p>Requirements include:</p>
<ul>
<li>A bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.</li>
</ul>
<ul>
<li>2–5 years of experience in application security, product security, software engineering with a security focus, or a related technical role.</li>
</ul>
<ul>
<li>Strong understanding of application vulnerabilities and mitigation strategies (OWASP Top 10, CWE).</li>
</ul>
<ul>
<li>Experience with CI/CD tooling, Git-based workflows, and modern development practices.</li>
</ul>
<ul>
<li>Familiarity with cloud security concepts and hands-on experience with at least one cloud platform (AWS, Azure, or GCP).</li>
</ul>
<ul>
<li>Experience with one or more programming languages such as Python, Go, Java, JavaScript/Typescript, or Ruby. (Java and Python preferred.)</li>
</ul>
<ul>
<li>Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning.</li>
</ul>
<ul>
<li>Knowledge of secure coding principles, API security, authentication, authorization, and secrets management.</li>
</ul>
<ul>
<li>Strong problem-solving skills and the ability to communicate technical issues clearly to developers and cross-functional stakeholders.</li>
</ul>
<ul>
<li>Understanding of agile development processes and working within engineering teams.</li>
</ul>
<ul>
<li>Ability to Travel: This role will require 25% in-person travel for purposes including but not limited to new hire onboarding, team and department offsites, customer engagements, and other company events.</li>
</ul>
<p>This role is based in our Boston office and follows a hybrid model, with an expectation of being onsite 1-2 days per week.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$130,000-$170,000 USD</Salaryrange>
      <Skills>CI/CD tooling, Git-based workflows, modern development practices, cloud security concepts, application security tools, secure coding principles, API security, authentication, authorization, secrets management, Python, Go, Java, JavaScript/Typescript, Ruby</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Starburst</Employername>
      <Employerlogo>https://logos.yubhub.co/starburst.io.png</Employerlogo>
      <Employerdescription>Starburst is a data platform company that unifies data across clouds and on-premises to accelerate AI innovation.</Employerdescription>
      <Employerwebsite>https://www.starburst.io/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/starburst/jobs/5119301008</Applyto>
      <Location>Boston, MA</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>8bf116df-95e</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>Job Title: Application Security Engineer</p>
<p>About the Role: The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. As an Application Security Engineer, you will partner closely with software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>
<p>Responsibilities:</p>
<ul>
<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>
<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>
<li>Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities</li>
<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>
<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>
<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>
<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>
<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>
</ul>
<p>Requirements:</p>
<ul>
<li>5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>
<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>
<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>
<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>
<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>
<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>
<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>
<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>
<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>
<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>
<li>Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>
<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>
<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>
<li>Experience building security tools, applications, and automated tools</li>
<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>
<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>
<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>
</ul>
<p>Annual Compensation Range:</p>
<p>$300,000-$405,000 USD</p>
<p>Logistics:</p>
<ul>
<li>Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience</li>
<li>Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience</li>
<li>Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position</li>
<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>
<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>
</ul>
<p>How to Apply:</p>
<p>If you&#39;re interested in this role, please submit your application through our website. We look forward to reviewing your application!</p>
<p>Note:</p>
<p>Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you&#39;re ever unsure about a communication, don&#39;t click any links,visit anthropic.com/careers directly for confirmed position openings.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$300,000-$405,000 USD</Salaryrange>
      <Skills>application security, infrastructure security, cloud-based security, containerized environments, programming languages, Python, Rust, Go, Java, threat modeling, secure design reviews, vulnerability management, bug bounty program, security policies, standards, playbooks, security awareness training, hands-on technical expertise, complex cloud environments, microservices architectures, Kubernetes, Docker, AWS, GCP, offensive security techniques, vulnerability testing, pen testing, red team exercises, AI/ML security risks, prompt injection, data poisoning, model extraction, security tools, applications, automated tools, software engineering principles, communication skills</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a company that creates reliable, interpretable, and steerable AI systems.</Employerdescription>
      <Employerwebsite>https://www.anthropic.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/4502508008</Applyto>
      <Location>Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>6d2bed6a-1bd</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies.</p>
<p>Responsibilities: Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in our applications Design and implement secure coding guidelines and best practices for development teams Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline Perform threat modeling and risk assessments for applications, developing mitigation strategies for potential risks Manage vulnerability tracking and remediation efforts, providing guidance to development teams Support incident response activities related to application security Stay current on emerging security threats and trends in cloud-native technologies and AI, continuously enhancing our security measures Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs) Address security concerns specific to AI and machine learning models, with a focus on the OWASP LLM Top 10</p>
<p>Basic Qualifications: Bachelor&#39;s degree in Computer Science, Cybersecurity, or a related field 3-5 years of experience in application security, with a strong focus on code security practices Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10) Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages Experience securing CI/CD pipelines and implementing DevSecOps practices Familiarity with software supply chain security and SBOM generation tools Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10 Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences</p>
<p>Preferred Skills and Experience: Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features Relevant security certifications (e.g., CSSLP, OSWE) Background in data privacy and compliance regulations relevant to cloud-native applications and AI systems Experience with GitOps and infrastructure-as-code security Familiarity with federated learning and privacy-preserving machine learning techniques Experience in building custom security tooling to enhance and automate security processes Interest in leveraging AI to automate security tasks and improve efficiency Contributions to open-source security projects or tools Experience in securing AI/ML models and data pipelines</p>
<p>Compensation and Benefits: $200,000 - $340,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$200,000 - $340,000 USD</Salaryrange>
      <Skills>Python, Rust, Secure coding practices, Application security frameworks, Common vulnerabilities, OWASP Top 10, CI/CD pipelines, DevSecOps practices, Software supply chain security, SBOM generation tools, Security testing tools, Static/dynamic code analysis, AI/ML security implications, OWASP LLM Top 10, Cloud platforms, Security certifications, Data privacy and compliance regulations, GitOps, Infrastructure-as-code security, Federated learning, Privacy-preserving machine learning techniques, Custom security tooling, AI automation, Open-source security projects, AI/ML model security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>xAI</Employername>
      <Employerlogo>https://logos.yubhub.co/xai.com.png</Employerlogo>
      <Employerdescription>xAI creates AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.</Employerdescription>
      <Employerwebsite>https://www.xai.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/xai/jobs/4559147007</Applyto>
      <Location>Palo Alto, CA</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>9eb58719-bef</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p><strong>About the role:</strong></p>
<p>The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. In this hands-on technical role, you will partner closely with software engineers and researchers to ensure security is a core consideration from initial design through implementation.</p>
<p>You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>
<p>Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You&#39;ll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions.</p>
<p><strong>Responsibilities:</strong></p>
<ul>
<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>
<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>
<li>Conduct secure design reviews and threat modeling. Identify and prioritise risks, attack surfaces, and vulnerabilities</li>
<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>
<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritise vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>
<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>
<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>
<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>
</ul>
<p><strong>You may be a good fit if you:</strong></p>
<ul>
<li>Have 5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>
<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>
<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>
<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>
<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>
<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>
<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>
<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>
<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>
<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>
<li>Advocate for security fundamentals like least privilege, defence-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>
</ul>
<p><strong>Strong candidates may also:</strong></p>
<ul>
<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>
<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>
<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>
<li>Experience building security tools, applications, and automated tools</li>
<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>
<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>
<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>
</ul>
<p>The annual compensation range for this role is $300,000 - $405,000 USD.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$300,000 - $405,000 USD</Salaryrange>
      <Skills>application security, infrastructure security, cloud security, containerized environments, secure coding practices, vulnerability management, bug bounty program, offensive security, modern application stacks, security tools, Kubernetes, Docker, AWS, GCP, Python, Rust, Go, Java, vulnerability testing, pen testing, red team exercises, AI/ML security risks, security tools, automated tools</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a rapidly growing organisation developing reliable, interpretable, and steerable AI systems. The company&apos;s mission is to create safe and beneficial AI for users and society.</Employerdescription>
      <Employerwebsite>https://job-boards.greenhouse.io</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/4502508008</Applyto>
      <Location>San Francisco, CA, Seattle, WA, New York City, NY</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
    <job>
      <externalid>1b3bc932-a1b</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We&#39;re looking for an Application Security Engineer to join the ElevenLabs Security team. In this role, you&#39;ll work at the intersection of security and software engineering, building systems and tooling that enable teams to ship secure software at high velocity.</p>
<p><strong>What you&#39;ll do</strong></p>
<p>You will:</p>
<ul>
<li>Design and build application security tooling and guardrails that integrate directly into modern development workflows, including environments that heavily leverage AI-assisted and agentic coding</li>
</ul>
<ul>
<li>Partner with Engineering and Infrastructure teams to review application architectures, develop threat models and build in secure by default patterns throughout the software development lifecycle</li>
</ul>
<ul>
<li>Identify, prioritise and remediate application security vulnerabilities, working directly with engineers and contributing to fixes where required, across the entire stack.</li>
</ul>
<p><strong>What you need</strong></p>
<ul>
<li>Strong software engineering background, with experience building and shipping production systems</li>
</ul>
<ul>
<li>Proven track record of building and scaling security programs or developer security tooling from scratch</li>
</ul>
<ul>
<li>Fluency in Python and TypeScript with the ability to read, write and maintain production quality code</li>
</ul>
<ul>
<li>Hands on experience in cloud-native environments (AWS or GCP), Kubernetes, and infrastructure-as-code (Terraform)</li>
</ul>
<ul>
<li>Solid understanding of application security, including discovery, exploitation and remediation. You should understand how to prioritise fixes without relying on CVE scores alone</li>
</ul>
<p><strong>Why this matters</strong></p>
<p>This role is a key part of our security team, and will play a critical role in ensuring the security of our products and services. You will have the opportunity to work with a talented team of engineers and security professionals, and to contribute to the development of our security program.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>software engineering, security, Python, TypeScript, cloud-native environments, Kubernetes, infrastructure-as-code, AI-assisted and agentic coding, developer security tooling, security program management</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>ElevenLabs</Employername>
      <Employerlogo>https://logos.yubhub.co/elevenlabs.io.png</Employerlogo>
      <Employerdescription>ElevenLabs is an AI research and product company transforming how we interact with technology. We have expanded from voice into three main platforms: ElevenAgents, ElevenCreative, and ElevenAPI.</Employerdescription>
      <Employerwebsite>https://elevenlabs.io</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://elevenlabs.io/careers/ed322919-002e-4d1e-819a-e9336cad7a4d/application-security-engineer</Applyto>
      <Location>United Kingdom</Location>
      <Country></Country>
      <Postedate>2026-03-05</Postedate>
    </job>
    <job>
      <externalid>b474ff4a-8ab</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>Perplexity is seeking a highly skilled, experienced and hands-on Application Security Engineer to join our dynamic security team, revolutionizing the way people search and interact with the internet. You’ll build the systems, tools, and processes that make security seamless for developers and strong by default, enabling rapid innovation while protecting our users at scale.</p>
<p><strong>What you&#39;ll do</strong></p>
<p>Design and implement scalable, developer-friendly security solutions that integrate directly into engineering workflows</p>
<p><strong>What you need</strong></p>
<ul>
<li>8+ years of experience in Application Security, Product Security, or similar roles</li>
<li>Deep understanding of secure software development practices, threat modeling, and common vulnerabilities (e.g., OWASP Top 10)</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$220K – $405K</Salaryrange>
      <Skills>Application Security, Product Security, Secure Software Development Practices, Threat Modeling, Common Vulnerabilities, Modern Authentication and Authorization Patterns, OAuth, OIDC, SSO, Zero Trust</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Perplexity</Employername>
      <Employerlogo>https://logos.yubhub.co/perplexity.com.png</Employerlogo>
      <Employerdescription>Perplexity is a dynamic company that is revolutionizing the way people search and interact with the internet. They are seeking a highly skilled Application Security Engineer to join their security team.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/perplexity/63abf041-c7ba-4bd6-840c-1a4ac7925dee</Applyto>
      <Location>San Francisco, London, New York City, Remote (United States), Serbia</Location>
      <Country></Country>
      <Postedate>2026-03-04</Postedate>
    </job>
  </jobs>
</source>