SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff security engineer, application security

Writer - New York, NY, United States - Hybrid - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Writer is an enterprise generative AI platform used by leading companies like Mars, Marriott, Uber, and Vanguard to build and deploy AI agents grounded in company data. As a Staff Security Engineer for Application Security, you'll be responsible for building the security foundations that protect Writer's AI systems at enterprise scale. You'll work at the intersection of application security, AI infrastructure, and developer enablement, partnering with engineering teams to embed security into every line of code. Your responsibilities include: - Conduct threat modeling sessions with product teams and design secure architectures for new AI features, ensuring security shapes product decisions from the start - Own and evolve the application security program, including establishing SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation to catch vulnerabilities before production - Partner with engineering teams to establish secure coding standards and create reusable security patterns and libraries that make it easier for developers to build securely by default - Design and recommend security features and products that help secure customer environments, serving as the advocate and vision for customer protection - Integrate and leverage AI agents to increase velocity for the security team and broader engineering organization, proactively minimizing risk while building products - Lead security assessments and penetration testing of Writer's applications, AI services, and APIs, identifying vulnerabilities and working collaboratively on remediation at scale - Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents - Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses This role reports to the head of security engineering and is hybrid from Writer's New York City, San Francisco, or Seattle offices. REQUIREMENTS: - Minimum 4 years of hands-on experience in application security engineering with a proven track record of securing large-scale production systems (bonus if from fast-growing startups or high-growth environments) - Understanding of developer experience and developer workflows; ability to reduce risk while considering engineering velocity - Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) with ability to read and review code across multiple languages, understanding both business logic and security implications - Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices - Excellent communication skills to translate complex security concepts into clear recommendations for technical and non-technical audiences - Builder's mindset focused on automation, scaling, and empowerment rather than creating bottlenecks; understanding that security enables the business - Alignment with Writer's values of Connect, Challenge, and Own - Open to Mid, Senior, and Staff level candidates

About Writer

AI / Data / Infrastructure; SaaS / Enterprise Software — enterprise generative AI platform for business teams.

Similar roles