Remote Jobs RockRemote Jobs Rock

Staff Application Security Engineer

🕒 2 days ago
Application SecurityDevsecopsKubernetesGoogle Cloud Platform

📜 Description

  • Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates
  • Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads
  • Lead the integration of security into CI/CD pipelines — code scanning, secret detection, software composition analysis, and infrastructure policy enforcement — partnering with engineering

🛠️ Requirements

  • 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teams
  • Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane)
  • Strong experience with Application Security tooling — dependency scanning, static analysis, and policy enforcement — integrated into CI/CD pipelines such as GitHub Actions and ArgoCD, and the ability to bridge engineering practices with Security Operations
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs), and familiarity with frameworks like MITRE ATT&CK
  • Strong grasp of cloud services (GCP preferred), especially securing data pipelines, model hosting endpoints, and related infrastructure
  • Proficiency with Infrastructure-as-Code (Terraform, Crossplane, or similar) and security scanning for cloud resources
  • Proficiency with scripting and automation (e.g., Python, Bash)
  • The ability to thoughtfully participate in technical discussions and drive towards data-driven decisions amidst ambiguity and competing priorities
  • Strong communication skills and empathy for developer needs, with a demonstrated ability to embed secure practices without creating friction
🕒 19 days ago

Company Description It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy.

AI SecurityThreat ModelingSecurity ArchitectureInternal AI Governance
Okta

Staff Product Security Engineer, Reviews

Okta👥 10,000+ employees🏢 Software Development
🕒 12 days ago

A successful candidate will have expertise in authentication protocols (SAML, OAuth, OIDC), threat modeling, and a strong desire to automate security processes by building tools that proactively identify vulnerabilities.

Security ReviewsThreat ModelingPenetration TestingSecure Code Reviews
Anthropic

Safeguards Enforcement Lead, Cyber Harms

Anthropic👥 10,000+ employees🏢 Research Services🤝 B2B
🕒 7 days ago

As an Enforcement Lead, you will manage enforcement actions to detect and mitigate misuse of AI systems for malicious cyber operations, while leading a team of Cyber Enforcement Analysts.

CybersecurityMalware AnalysisExploit DevelopmentSQL
Servicenow

Staff Security Engineer (Compliance) - Moveworks

Servicenow👥 10,000+ employees🏢 Computer Software
📅 Aug 4

It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy. That moment inspired Fred to build a company that could do that for everyone—freeing people from busywork.

Security ComplianceRisk ManagementISO 27001ISO 42001

Trusted by Remote Workers