Starburst

Application Security Engineer

Starburst
Apply
5 months ago
Boston, MA, USAMid Level / Senior
H1B sponsor

Base Salary

$130k - $170k/yr

Responsibilities

  • Integrate application security best practices and automated security checks into the software development lifecycle.
  • Support and maintain SAST, DAST, SCA, secrets-scanning, and other application security tooling.
  • Conduct secure code reviews, threat modeling sessions, and application architecture assessments.
  • Develop and maintain security automation, guardrails, reusable components, tools, pipelines, and workflows.
  • Define and improve secure coding standards and application hardening practices.
  • Improve application-level logging, telemetry, monitoring, detection, and alerting.
  • Support incident response for application vulnerabilities through verification, triage, and remediation.
  • Research emerging threats, vulnerabilities, and application and product security practices.
  • Create security requirements, guidelines, and remediation playbooks.
  • Participate in security reviews, compliance-driven assessments, and architectural walkthroughs.
  • Collaborate with engineering and product teams on secure deployment and continuous improvement.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.
  • 2–5 years of experience in application security, product security, security-focused software engineering, or a related technical role.
  • Strong understanding of application vulnerabilities and mitigation strategies, including OWASP Top 10 and CWE.
  • Experience with Git-based workflows and modern development practices.
  • Familiarity with cloud security and hands-on experience with AWS, Azure, or GCP.
  • Experience with Python, Go, Java, JavaScript/TypeScript, or Ruby; Java and Python are preferred.
  • Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency-scanning tools.
  • Knowledge of secure coding, API security, authentication, authorization, and secrets management.
  • Ability to communicate technical issues clearly to developers and cross-functional stakeholders.
  • Understanding of agile development processes and experience working within engineering teams.
  • Ability to travel approximately 25% for onboarding, offsites, customer engagements, and company events.

Benefits

  • Hybrid work based in the Boston office with an expectation of being onsite 1–2 days per week.
  • 25% in-person travel may be required for onboarding, offsites, customer engagements, and company events.
  • Equity packages in the form of ISOs.
  • Comprehensive benefits including flexible paid time off and stock grants.
Starburst

About Starburst

501-1,000 employees

Starburst builds an enterprise data platform that lets teams query and govern distributed data across clouds and on‑prem systems without copying it, powered by Trino and Apache Iceberg. It sells commercial Trino-based software and a managed cloud service for federated SQL, data lakehouse analytics, and governance. Founded in 2017 and headquartered in Boston, the privately held company serves global enterprises; customers include Comcast and Citigroup.

Contact me