3 months ago
Base Salary
$190k - $273k/yr
Responsibilities
- Own and continuously improve Apollo’s secure software development lifecycle and application-security guardrails.
- Perform application security reviews, threat modeling, and deep code-level analysis for product, platform, and AI features.
- Provide security architecture guidance and maintain secure design, code review, and risk-management standards.
- Manage vulnerabilities from internal reviews, bug bounty programs, penetration tests, SCA/runtime findings, and other research signals through validation, prioritization, remediation, and verification.
- Read code, explain root causes, propose fixes, and directly implement or support remediation for complex vulnerabilities.
- Perform offensive security testing, exploit development, bypass testing, and red-team-style validation of applications and fixes.
- Configure and improve AppSec tooling, SAST coverage, integrations, dashboards, and workflow controls.
- Build or refine security tooling, automations, and workflow enrichments to reduce manual effort and improve signal quality.
- Use AI-assisted workflows responsibly to scale security and engineering processes.
- Embed AI-specific security checks covering input and output handling, AI-exposed APIs, prompt and response guardrails, abuse, and data-exfiltration paths.
- Support security enablement for engineers and security champions through secure coding, AppSec, and AI-safety content.
- Partner with Engineering, Product, Platform, Data, Legal, and security teams on AppSec priorities and AI security controls.
- Produce documentation, metrics, and written narratives that improve AppSec visibility and decision-making.
Requirements
- At least 5 years of software engineering or application security experience with meaningful hands-on application security depth in modern SaaS environments.
- Strong software development skills and the ability to read, write, and ship production code.
- Ruby experience is highly valuable; Python or similar scripting ability is a plus.
- Strong Linux and cloud fundamentals, ideally in GCP-backed environments.
- Deep familiarity with application security issues, secure design, authentication and authorization, vulnerability management, and developer security tooling.
- Experience with deep code review, penetration testing, exploit-oriented validation, direct vulnerability remediation, and bypass or variant analysis.
- Experience managing findings from bug bounty programs, penetration tests, internal reviews, or automated security tooling through closure and verification.
- Experience using AI-assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale.
- Experience securing AI-powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring.
- Strong written and verbal communication, stakeholder management, and cross-functional influencing skills.
- Experience supporting security reviews for AI-native products, internal agents, or AI-assisted engineering workflows is preferred.
- Experience improving secure-by-design practices and AppSec observability is preferred.
- Experience with security training, developer enablement, or security champion programs is preferred.
- Relevant security certifications are a plus.
Benefits
- Equity may be available.
- Company bonus may be available.
- 401(k) plan.
- At least 10 paid holidays per year, flex PTO, and parental leave.
- Employee assistance and wellbeing benefits.
- Global travel coverage.
- Life, AD&D, STD, and LTD insurance.
- FSA/HSA and medical, dental, and vision benefits.
- US pay ranges vary by location: Tier 1 includes San Francisco, New York City, and Seattle; Tier 2 includes other US locations.
Tech Stack
Categories
About Apollo.io
Apollo.io builds a go-to-market platform that pairs a large B2B contact database with sales engagement, enrichment, and sequencing tools for revenue teams. Offered as a SaaS subscription, it serves sales and marketing organizations that need prospect data and outbound automation; the company is privately held, founded in 2015, headquartered in San Francisco, and raised a Series D funding round in 2023.
