Skip to main content

Vannevar

Application Security Engineer

Remote (Remote)$160k–$210kfull-timemidAdded today

About this role

Vannevar seeks an Application Security Engineer to embed security practices across their AI-powered SaaS platform. You'll implement automated security scanning, lead threat modeling with development teams, and coordinate vulnerability response to enable secure, rapid feature delivery.

What you'll do

  • Deploy SAST, SCA, secrets-scan, DAST, and container/IaC checks into CI/CD pipelines
  • Conduct threat modeling sessions and perform security code reviews with development teams
  • Drive shift-left vulnerability detection and remediation throughout the SDLC
  • Coordinate application and infrastructure security issues with DevOps teams
  • Support incident response for product security issues and document lessons learned

What they're looking for

  • Application/Product Security (5+ years)
  • DevSecOps practices and container security
  • SAST, SCA, DAST, and secrets scanning tools
  • GitHub Actions
  • Python and TypeScript/JavaScript
  • Threat modeling
  • Security communication and risk translation
  • Web application security

Benefits

  • Health, dental, and vision insurance
  • 100% remote work across the US
  • 401(k) matching
  • Unlimited PTO
  • Mental health benefits
  • Pet and childcare reimbursement during travel
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Vannevar

Vannevar builds defense technology platforms that leverage data collection, agentic AI, and machine learning to support national security and military operations. The company is hiring Backend Engineers, Product Engineers, Machine Learning Engineers, and Forward Deployed Engineers to develop and modernize mission-critical software systems that enable faster, data-driven decision-making for warfighters.

View all jobs at Vannevar

Likely interview questions

  • Walk us through your experience implementing shift-left security in a CI/CD pipeline—what tools did you use and what challenges did you encounter?
  • How do you approach communicating security risks to engineers who may have limited security background?