
Application Security Engineer
MyFitnessPal2 days ago
Remote, United StatesMid Level
Base Salary
$90k - $130k/yr
Responsibilities
- Own application security vulnerability management, including triaging SAST, SCA, DAST, and mobile security findings, assigning severity and due dates, proposing remediations, and driving issues to resolution.
- Operate and expand the bug bounty program by scoping engagements, triaging submissions, validating findings, and coordinating with vendors.
- Use AI and agentic tooling to accelerate vulnerability triage, enrichment, automated remediation support, and security of AI-assisted development practices.
- Build and maintain security automation with SOAR platforms and Python for vulnerability intake, notifications, SLAs, metrics, and reporting.
- Partner with product engineering teams on remediation, security reviews, secure coding practices, documentation, and training.
- Administer and tune application security tooling across the software development lifecycle and evaluate new security technologies.
- Support identity and access management workflows and related automation.
Requirements
- 2–4 years of experience in security engineering, application security, software engineering, or a closely related role.
- Understanding of SAST, DAST, SCA, penetration testing, vulnerability triage, investigation, remediation, and vulnerability management.
- Knowledge of secure development practices for web and mobile applications, including OWASP Top 10 and OWASP MASVS.
- Experience with AI- or agentic-assisted tooling, such as Claude Code, AI coding assistants, LLM-powered workflows, or agentic automation.
- Familiarity with auto-scaling cloud microservices, containerization, Kubernetes, and infrastructure as code.
- Ability to communicate findings and remediation guidance, collaborate cross-functionally, and document technical details for technical and non-technical audiences.
- Education and/or certifications equivalent to a BS in Computer Science, Information Systems, or a related field.
- Preferred experience includes security process automation with Python or SOAR platforms, security scanning in CI/CD pipelines, GitHub Actions, orchestration tools, and bug bounty program operations.
- GIAC certifications such as GWEB or GCIH, OSCP, CSSLP, Security+, and vendor-specific certifications are preferred.
Benefits
- Full-time employee benefits include healthcare, parental planning, mental health benefits, an annual performance bonus, a 401(k) plan with employer match, responsible time off, and monthly wellness and technology allowances.
- Flexible time-off policy and opportunities for in-person team connections, with an annual company gathering.
- Two paid volunteer days per calendar year.
- Mentorship program, virtual learning and development resources, and training opportunities.
- Paid maternity and paternity leave and fertility-related assistance.
- Monthly wellness allowance, mental health days, and access to MyFitnessPal Premium.
- Medical, dental, and vision benefits and a retirement savings program with employer match.