SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Shield AI, a venture-backed defense-tech company, is seeking a Staff Application Security Engineer to build and advance a scalable, developer-centered application security program. This is a Staff-level individual-contributor role with significant influence across engineering, security, product, and technology leadership.
You will establish company-wide secure software development lifecycle (SDLC) policies, standards, and control objectives, then translate them into practical engineering practices. Working directly with product, platform, and development teams, you will improve secure development and software supply-chain maturity while ensuring security controls are practical, measurable, and integrated into existing workflows.
Key responsibilities include:
- Establish and continuously improve company-wide secure SDLC policies, standards, procedures, and evidence requirements
- Translate security policy into clear, achievable requirements for development teams without creating unnecessary delivery friction
- Assess development team maturity across CI/CD pipelines, source control, build environments, and release processes; define and lead improvement roadmaps
- Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, and developer enablement materials
- Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings
- Evaluate, implement, tune, and operationalize application-security tooling (SAST, DAST, SCA, secrets detection, IaC scanning, container security, API security)
- Ensure security tooling produces actionable findings without excessive false positives
- Lead threat modeling, security requirements definition, and secure design/architecture reviews for high-risk applications
- Establish risk-based vulnerability management processes with severity criteria, remediation SLOs, compensating controls, and exception management
- Develop processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies
- Establish open-source software governance including component inventory, license identification, and approval workflows
- Mature software supply-chain security practices (SBOMs, VEX, build provenance, artifact signing, SLSA-aligned controls)
- Partner with DevOps and platform engineering to secure CI/CD pipelines
- Establish requirements for secure source-code repositories, build systems, dependency registries, and deployment pipelines
- Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, and product-security incident response
- Create and lead a security champions program providing developers with secure-coding guidance, training, and tools
- Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, and program maturity
- Support customer, regulatory, audit, and assurance activities related to secure development and software supply-chain practices
Requirements:
- 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or closely related field
- Demonstrated experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams
- Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles
- Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices
- Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling
- Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows
- Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition
- Knowledge of common application-security risks (authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, business-logic vulnerabilities)
- Experience with software supply-chain security concepts (SBOMs, dependency provenance, build integrity, artifact signing, release attestations, secure artifact management)
- Experience with open-source software risk management (vulnerable dependencies, transitive dependencies, license obligations, governance processes)
- Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable secure-development and supply-chain security frameworks
- Ability to read and assess production code and scripts in one or more modern programming languages
- Strong written and verbal communication skills, including ability to explain technical risk and tradeoffs to developers, leaders, auditors, and nontechnical stakeholders
Preferred qualifications:
- Experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls
- Experience with VEX, CSAF, SBOM formats (SPDX or CycloneDX), and component or vulnerability intelligence workflows
- Experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code
- Experience with common source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms
- Experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies
- Experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements
- Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance product environments
- Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials