Jobedly Post a Job

Staff Application Security Engineer

Censys · Remote
RemoteFull-timeEngineeringGeneral$179,000–$241,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Staff Application Security Engineer role

Staff Application Security Engineer positions focus on delivering results in their domain. This page aggregates open Staff Application Security Engineer roles and what employers typically expect.

Company Background Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide. Location: This position is remote within the United States or Canada. At Censys , we’re on a mission to provide best in class internet visibility and intelligence to the global security community. Our platform helps security teams uncover hidden threats, gain actionable insights, and build proactive defense strategies. Trusted by organizations worldwide, Censys cuts through the noise to surface the most critical risks, enabling teams to respond faster, and stay ahead of attackers. We’re constantly pushing the boundaries of what’s possible to help our customers see and secure the internet more clearly than ever before. Role Summary: Censys is seeking a Staff Application Security Engineer to join our Infrastructure and Operations Platform (SRE) team. In this role, you’ll own the application security strategy for how Censys builds and ships software — designing the secure paths, guardrails, and automation that let our engineers develop and deploy quickly, confidently, and securely. You’ll set technical direction across the software lifecycle, from infrastructure-as-code and container security to secure deployment workflows and the security of our AI/ML-enabled services. As a security company, we hold ourselves to the standard we help our customers achieve; this role is central to making that real. We expect all of our employees to consider customer happiness as our primary goal and to come to work every day eager to learn and educate, helping to make us a better organization every day. What You’ll Do: Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads Lead the integration of security into CI/CD pipelines — code scanning, secret detection, software composition analysis, and infrastructure policy enforcement — partnering with engineering teams to adopt them without friction Deliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organization Set the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance tracking Partner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracy Provide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teams Participate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readiness What You’ll Bring: 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teams Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane) Strong experience with Application Security tooling — dependency scanning, static analysis, and policy enforc…

Salary estimate

$179,000 – $241,000/yr
Provided by the employer.

Skills for this role

GCPKubernetesCi/CdLeadershipSecurityAutomation

Resume tips for Staff Application Security Engineer applicants

Interview preparation

Prepare concrete STAR-format stories that show Staff Application Security Engineer outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Staff Application Security Engineer problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Censys

Censys is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles