SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Lucid Software is seeking a Senior Application Security Engineer to serve as a trusted security partner embedded in the development lifecycle. You will work closely with engineering, product, and corporate teams to build security into products from the start, helping teams move fast without taking on undue risk.
Key responsibilities include conducting thorough security architecture and design reviews for new and evolving product features, surfacing risk early and recommending practical mitigations. You will drive a risk-based approach to application security, helping teams understand and prioritize vulnerabilities by business impact. You'll serve as a subject matter expert on application security topics for product, engineering, legal, and leadership stakeholders, and mentor engineers across the organization on secure development practices to foster a culture where security is everyone's responsibility.
You will build and maintain strong, collaborative partnerships with product and engineering teams, serving as their primary security resource throughout the software development lifecycle. You'll mature Lucid's Secure Software Development Lifecycle (SSDLC), including secure coding standards, security requirements, and developer security education. Additional responsibilities include ensuring AI tools and processes are implemented within acceptable risk limits, leading product design reviews to ensure security considerations are inherent in feature design, developing and maintaining scalable security tooling and automation to integrate security controls into CI/CD pipelines, and leading and training engineers in Lucid's security champions program.
Lucid's products include the Lucid Visual Collaboration Suite (Lucidchart and Lucidspark) and airfocus, which help teams see and build the future by turning ideas into reality. The company is a hybrid workplace that promotes a healthy work-life balance.
REQUIREMENTS:
- 5+ combined years of experience in software engineering, application security, product security, or a closely related field within a SaaS environment
- Proven track record of building trusted, effective relationships with product and engineering teams
- Experience securing web applications built on modern frameworks and cloud-native architectures (particularly AWS)
- White-box penetration testing experience
- Strong understanding of SSDLC principles and experience implementing or maturing secure development programs
- Ability to conduct meaningful security architecture and design reviews, with a focus on identifying risk early in the development process
- Solid understanding of common application vulnerabilities and attack techniques (OWASP Top 10, API security, authentication/authorization flaws, etc.)
- Experience integrating security tooling into modern CI/CD pipelines
- Risk-focused mindset: able to articulate security risk in business terms and help teams make informed, pragmatic decisions
- Familiarity with AI security risks and emerging attack surfaces, including securing agentic systems, MCP, and LLM-powered workflows
- Strong written and verbal communication skills
PREFERRED QUALIFICATIONS:
- Development experience in modern tech stacks
- Practical knowledge of relevant security frameworks and compliance standards (OWASP ASVS, NIST 800-53, SOC 2, GDPR)
- Relevant certifications such as OSCP, BSCP, GWEB, PNPT, or similar hands-on security-focused certifications
- Experience with bug bounty program management
- Bachelor's degree in Computer Science, Information Security, or a related field