Application Security Engineer / Architect (DevSecOps)
Clear Streetabout 3 hours ago
Base Salary
$175k - $210k/yr
Responsibilities
- Own security controls within CI/CD pipelines and maintain pipeline-as-code tooling.
- Work with engineers to identify and remediate vulnerabilities in application source code.
- Manage the vulnerability lifecycle, including triaging findings and tracking remediation.
- Lead cloud security efforts and enforce cloud security best practices.
- Maintain and tune security tooling including SAST/DAST scanners and container security platforms.
- Build automation and AI-based tools to scale DevSecOps operations.
- Define secure infrastructure-as-code standards and enforce them via policy-as-code.
- Participate in threat modeling sessions and security design reviews.
- Support incident response activities related to application and cloud security events.
- Contribute to security documentation and developer-facing guidance.
Requirements
- 7+ years of experience in a DevSecOps, application security, or cloud security engineering role.
- Hands-on experience with CI/CD platforms like GitHub Actions or Jenkins.
- Proficiency with at least one major cloud provider and its native security services.
- Experience with SAST/SCA tools and interpreting findings.
- Working knowledge of container and Kubernetes security.
- Scripting skills in Python, Bash, or similar for automation.
- Familiarity with IaC tools and policy frameworks.
- Understanding of OWASP Top 10 and common vulnerability classes.
- Strong communication skills to explain security risks to non-security audiences.
Benefits
- Competitive compensation packages and company equity.
- 401k matching and gender-neutral parental leave.
- Full medical, dental, and vision insurance.
- In-office benefits including lunch stipends and fully stocked kitchens.
- Happy hours and a great office location with amazing views.