Summary
As a Staff Application Security Engineer, the full-time position will own the technical strategy to secure critical attack surfaces, lead architecture reviews, and design AI agents to enhance the secure software development lifecycle, with a hybrid work arrangement based in New York.Key responsibilities:Own and evolve the Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expertLead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and servicesDesign and build AI agents throughout the SDLC for automated threat modeling and secure code generationRequired qualifications:Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindsetStrong background in application security best practices and familiarity with common vulnerabilitiesDeep code review proficiency in Scala, Java, Go, or other common languages, with hands-on experience in Python or GoExperience implementing custom detection and prevention application security controls beyond OWASP Top 10Typically 7-10+ years of experience in application security, product security, or similar roles
Job Description
As a Staff Application Security Engineer, the full-time position will own the technical strategy to secure critical attack surfaces, lead architecture reviews, and design AI agents to enhance the secure software development lifecycle, with a hybrid work arrangement based in New York.Key responsibilities:Own and evolve the Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expertLead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and servicesDesign and build AI agents throughout the SDLC for automated threat modeling and secure code generationRequired qualifications:Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindsetStrong background in application security best practices and familiarity with common vulnerabilitiesDeep code review proficiency in Scala, Java, Go, or other common languages, with hands-on experience in Python or GoExperience implementing custom detection and prevention application security controls beyond OWASP Top 10Typically 7-10+ years of experience in application security, product security, or similar roles
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Senior Interface Testing Analyst (48)
- all cities, Washington
- Virtual Vocations
- Aug 12, 2026
-
FSO / Security Lead w/active Top Secret clearance
- Washington, DC
- LMI
- Aug 12, 2026
-
Emerging Risk & Controls Analyst Secret Clearance (DoD)
- District Heights, Maryland
- Lynch Consultants
- Aug 12, 2026
-
Action Officer - Navy Yard, Washington, D.C.
- Washington, DC
- Serco Inc.
- Aug 12, 2026
-
Adversary Hunter (21)
- all cities, Maryland
- Virtual Vocations
- Aug 12, 2026
-
Dispatch Specialist (26)
- all cities, Mississippi
- Comcentric
- Aug 12, 2026