SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff/Lead Application Security Engineer

Beacon Software - San Francisco, CA, United States - In-office - posted 2026-08-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Beacon Software seeks its first dedicated Staff Application Security Engineer to establish and lead the company's product security strategy and program. You will be responsible for securing Beacon's own engineering operations and the products of its portfolio companies, each with independent stacks and engineering teams. Key responsibilities include: - Secure Design & Architecture: Lead threat modeling and security architecture reviews for new products and platform initiatives. Define standards for authentication, authorization, encryption, and tenant isolation across the portfolio. - Acquisition Assessment: Own security reviews of newly acquired codebases and cloud environments, establishing baseline posture, material risks, and remediation paths. - Code & Security Review: Perform secure code reviews targeting authorization and business logic flaws. Manage external penetration testing partners and drive remediation of findings. - AI Security: Assess AI features across products, including agent architectures, model/tool access, delegated credentials, and data reachability. - Vulnerability Management: Own end-to-end vulnerability programs including intake, severity assessment, prioritization, remediation SLAs, and reporting. Drive fixes through engineering teams sustainably. - Tooling & Automation: Establish standards for SAST, DAST, SCA, and secrets scanning integrated into CI/CD. Build automation enabling one person to cover a multi-team portfolio, including routine fix PRs and findings routing. - Enablement: Write secure coding standards and training for engineering teams. - Incident Response: Serve as product security expert during incidents from investigation through remediation. - Compliance Partnership: Work with GRC to produce audit evidence and security reviews without letting compliance drive the roadmap. You should have expert knowledge of web/API security, identity and access design (authentication, authorization, RBAC/ABAC), and applied cryptography. Experience securing cloud and containerized workloads is essential. You ship production code yourself, can set architecture across many codebases, and have a track record of driving security work to completion across engineering organizations outside your reporting line. You leverage AI as part of your workflow with informed opinions on where it helps.

Similar roles