SlipstreamJobsFresh Startup & VC-Backed Jobs

Application Security Engineer

SmartRent - Phoenix, AZ, United States - Hybrid - posted 2026-08-23

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

SmartRent is a NYSE-listed proptech company providing an end-to-end platform for the rental housing industry, combining software, integrated hardware, and implementation services. The Application Security Engineer will be responsible for protecting the SmartRent platform through comprehensive application security management, risk assessment, and compliance activities. Key responsibilities include developing and executing application security strategy aligned with business objectives; maintaining secure coding standards and SDLC practices; conducting code reviews to identify vulnerabilities (SQL injection, XSS, access control weaknesses); triaging and supporting remediation of security issues identified through SAST, DAST, and SCA tools; managing application security workflows and ticket prioritization; maintaining the responsible disclosure program; collaborating on threat modeling and attack path analysis; leading investigation and mitigation of application-level security incidents; providing guidance on security controls for AWS cloud infrastructure and IoT hardware; conducting regular risk assessments; researching emerging cybersecurity threats; performing adversarial testing and security validation; and implementing security guardrails for LLM integrations. The role requires 4–6 years of application security experience, including policy development and cross-functional collaboration with engineering teams. Required skills include identifying and remediating vulnerabilities across modern languages (Elixir, JavaScript, Ruby, Python); deep knowledge of OWASP Top 10 and API Top 10; hands-on experience with SAST/DAST/SCA tools (GHAS, Burp Suite, Fortra); AWS security controls and WAF experience; vulnerability disclosure/bug bounty program management; and strong communication skills. Preferred qualifications include security certifications (CSSLP, GIAC GWAPT, CEH), CloudFlare/AWS expertise, SDLC integration experience, and threat modeling background.

Similar roles