Vannevar
Application Security Engineer
About this role
Vannevar seeks an Application Security Engineer to embed security practices across their AI-powered SaaS platform. You'll implement automated security scanning, lead threat modeling with development teams, and coordinate vulnerability response to enable secure, rapid feature delivery.
What you'll do
- Deploy SAST, SCA, secrets-scan, DAST, and container/IaC checks into CI/CD pipelines
- Conduct threat modeling sessions and perform security code reviews with development teams
- Drive shift-left vulnerability detection and remediation throughout the SDLC
- Coordinate application and infrastructure security issues with DevOps teams
- Support incident response for product security issues and document lessons learned
What they're looking for
- Application/Product Security (5+ years)
- DevSecOps practices and container security
- SAST, SCA, DAST, and secrets scanning tools
- GitHub Actions
- Python and TypeScript/JavaScript
- Threat modeling
- Security communication and risk translation
- Web application security
Benefits
- Health, dental, and vision insurance
- 100% remote work across the US
- 401(k) matching
- Unlimited PTO
- Mental health benefits
- Pet and childcare reimbursement during travel
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Vannevar
Vannevar builds defense technology platforms that leverage data collection, agentic AI, and machine learning to support national security and military operations. The company is hiring Backend Engineers, Product Engineers, Machine Learning Engineers, and Forward Deployed Engineers to develop and modernize mission-critical software systems that enable faster, data-driven decision-making for warfighters.
- Website
- vannevar.ai
Likely interview questions
- Walk us through your experience implementing shift-left security in a CI/CD pipeline—what tools did you use and what challenges did you encounter?
- How do you approach communicating security risks to engineers who may have limited security background?