SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 155,000 - 400,000 / annual
Sentry is an application monitoring platform trusted by 200,000+ organizations to help developers fix errors and performance issues before users notice. The Security Team is responsible for securing Sentry's customers, code, and infrastructure. As a Security Engineer on this small but growing team, you'll work across application and platform security domains with broad scope and high autonomy.
You will support and mature Sentry's security review program, including secure code review, architecture review, and threat modeling. You'll help build processes, tooling, and culture that make security a natural part of the development and operations workflow. You'll contribute to mature vulnerability management practices: intake, triage, prioritization, remediation tracking, and support of the bug bounty and responsible disclosure program.
You'll advocate for secure-by-design principles by partnering with engineering and product teams to embed security early in the development lifecycle and integrate security tooling into developer and CI/CD workflows. You'll validate and reproduce application and infrastructure security findings through scanning, manual testing, and supporting penetration testing across Sentry's application, SDKs, and cloud-based platform.
You'll help evaluate and respond to emerging threats relevant to application security, including novel attack surfaces introduced by Sentry's agentic product features and AI-assisted engineering practices. The role requires operating cross-functionally, building relationships, and influencing with technical expertise in a developer-forward culture. You should reach for automation first and prefer to drive work end-to-end with ownership.
Required: 2+ years designing, building, or securing complex applications and cloud systems; CS degree or equivalent; hands-on experience with security reviews, SDLC practices, secure CI/CD, architecture reviews, threat modeling, vulnerability management, or bug bounty programs; programming proficiency in at least one language with ability to read Python, Typescript, Go, or Rust; familiarity with distributed cloud technology (AWS, GCP, Azure, Kubernetes, Docker, Terraform) and cloud security concepts.