
Staff Application Security Engineer
Henry Schein One5 hours ago
Remote, United StatesStaff+
Base Salary
$140k - $190k/yr
Responsibilities
- Develop, implement, maintain, and govern the application security program across research, development, QA, support, and IT systems.
- Advise on secure product and architecture design and conduct architecture security reviews, security-focused code reviews, and security testing.
- Partner with engineering and product teams on security systems, secure code, threat models, risk assessments, and security posture.
- Monitor software usage, conduct forensic analysis, and track emerging web and client application security standards and practices.
- Provide leadership and guidance to security, development, systems, support, and QA teams while mentoring junior security engineers.
- Evaluate and govern the secure use of AI-assisted development tools and leverage AI/ML tools for security testing, threat modeling, and code review.
Requirements
- 8+ years of relevant information security and/or software engineering experience.
- Fluency with AI/LLM security risks, including OWASP Top 10 for LLM Applications, prompt injection, model poisoning, and data exfiltration.
- Experience evaluating or securing AI-powered application features, AI coding assistants, or responsible AI/ML data handling and privacy practices.
- Strong knowledge of secure application programming, coding lifecycles, security architecture, software and network architecture, authentication, threat assessment, risk management, and security processes.
- Advanced knowledge of multiple operating systems and hosting environments, plus knowledge of reverse engineering techniques and tools.
- Ability to implement code from technical specifications, work with data storage formats and tools, and understand programming languages used in secured products.
- Ability to communicate security objectives and technical concepts to varied audiences and complete the technical challenge.
- Preferred: bachelor’s degree in Computer Science or Information Security.
- Preferred: one or more relevant certifications such as CISSP, CEH, PNPT, OSWE, GWAPT, OSED, or OSCP.
Benefits
- Health coverage, retirement savings with company match, paid time off, parental leave, wellbeing resources, education support, and additional benefits.
- Remote within the United States with up to 10% travel as needed.
- Eligible for a bonus target.