← Back to job listings
ME
Security Engineer
Merge · San Francisco, United States
About The Role
Join Merge as a Security Engineer, where you will be the primary owner of product and application security across our platform. You will work closely with our Head of Security, Engineering, and Product teams to identify and fix vulnerabilities, shape secure development practices, and ensure our AI-powered products are built with strong security guarantees. You will conduct security reviews, drive vulnerability identification and remediation, build and mature our application security program, and operate our bug bounty program. Additionally, you will support infrastructure and cloud security as needed.
- Assumer la responsabilité principale de la sécurité des produits et des applications sur la plateforme de Merge, y compris les API, les intégrations, les outils d'agent et les fonctionnalités alimentées par l'IA.
- Conduire des examens de sécurité, des modélisations de menaces et des revues de code, en mettant l'accent sur les vulnérabilités au niveau de l'application, et diriger l'identification et la remédiation des vulnérabilités tout au long du cycle de vie du développement logiciel.
- Construire et faire évoluer le programme de sécurité des applications de l'entreprise, y compris les outils SAST/DAST, les tests de sécurité dans CI/CD, et fournir des conseils en matière de sécurité aux développeurs.
- Experience conducting threat modeling and secure code reviews
- Bonus: experience with AI/LLM security, agent security, or securing data-heavy API platforms
- Experience with and a desire to code in at least one major programming language. You should be comfortable reading and writing code, not just running scanners
- 3–6+ years of security engineering experience with a strong focus on product or application security
- Hands-on experience with application security tooling (SAST, DAST, SCA) and integrating security into CI/CD pipelines
- Interest in learning and supporting other areas of Security where needed
- Experience in a SaaS or API-driven environment; familiarity with multi-tenant systems and the security challenges they present
- Deep familiarity with application security concepts: OWASP, common vulnerability classes, secure API design, auth and authorization patterns
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring