AlphaSense

Senior Application Security Engineer

AlphaSense
Apply
3 months ago
Remote, United StatesSenior
H1B Sponsor

Base Salary

$157k - $216k/yr

Responsibilities

  • Own and continuously tune the SAST, SCA, secrets-detection, and SBOM pipeline and enforce deterministic security gates for all pull requests.
  • Review human- and agent-authored pull requests, identify semantic security violations, and drive recurring findings to platform-level fixes.
  • Secure AI-assisted development involving Claude Code, Cursor, Copilot, MCP servers, autonomous coding agents, and agent harnesses.
  • Create and implement policies for prompt-injection defense, MCP scope and credential governance, agent identity, credential inheritance, secret leakage, and audit attribution.
  • Threat model AI features, agent gateways, MCP connector architecture, and research-platform workflows, while scaling the threat-modeling framework across engineering.
  • Build developer security training and embed security acceptance criteria, agent scope declarations, and verification hooks into product-development processes.
  • Integrate code-security signals with infrastructure, contract, behavioral, adversarial-simulation, data-segmentation, and GRC teams.
  • Support DAST deployment, API penetration testing, bug-bounty intake, threat-intelligence integration, and the customer-facing security posture dashboard.
  • Respond to application-layer incidents, agentic behavior anomalies, and third-party integration compromises, including forensic investigation and post-incident hardening.

Requirements

  • At least 6 years of engineering experience, including 4 or more years in a dedicated AI Application Security or Product Security role at a SaaS or cloud-native company.
  • Recent hands-on development experience with fluency in at least two of Python, TypeScript / JavaScript, Java / Kotlin, or Go, plus comfort with Terraform, Helm, and Kubernetes manifests.
  • Hands-on experience building, integrating, or operating agentic AI tooling and MCP systems, including relevant security controls such as prompt-injection defenses or output sanitization.
  • Production operation of a SAST / SCA pipeline at scale, including rule authoring, false-positive tuning, and CI/CD integration.
  • Demonstrated ownership or substantial contribution to a threat-modeling or developer security training program.
  • Strong written communication skills for authoring policies, guidance, runbooks, and actionable pull-request comments.
  • Experience with API security, DAST, container and Kubernetes security, or AWS security is preferred.
  • Open-source contributions, deterministic compliance-gate experience, customer-facing security posture work, regulated-industry experience, public writing or speaking, and pre-IPO experience are preferred.
  • Familiarity with SOC 2 Type II, ISO 27001:2022, ISO 42001, SOX, or GDPR is preferred.
  • OSWE, OSCP, CSSLP, AWS Security Specialty, or CISSP certification is preferred.

Benefits

  • Remote-first work arrangement with high autonomy.
  • Performance bonus, equity, and benefits are offered.
  • Foundational hire with a clear path to Staff / Tech Lead.
AlphaSense

About AlphaSense

1,001-5,000 employees

AlphaSense is the technology behind the business world’s most important decisions – from Wall Street to boardrooms across every major industry. Trusted by over 6,500 leading companies – including 88% of the S&P 100, 80% of top global banks, and all 20 of the world’s largest pharmaceutical firms – our AI search and market intelligence platform empowers business leaders to move faster and with greater confidence by delivering the right insights at the right moment. Whether investing, acquiring, advising, or launching, AlphaSense fuels the decisions where clarity creates competitive edge. Headquartered in New York City, AlphaSense employs over 2,500 people across offices in the U.S., U.K., Finland, India, and Singapore. For more information, please visit www.alpha-sense.com.

Contact me