Skip to content
← Back to job listings

Senior Security Engineer (Application Security)

Smartsheet · United States

External listingfull-timeabout 1 month ago

About The Role

Join Smartsheet, a leading SaaS platform, as a Senior Security Engineer II in the Application Security team. In this role, you will leverage your expertise in securing AI-integrated systems and deploy AI and automation to drive risk visibility and reduction. You will conduct security reviews, deliver application security assessments, advance CI/CD pipeline security, and run bug bounty operations. This is a high-ownership, technically demanding role for an experienced application security engineer.

  • Conduire des examens de sécurité et des modélisations de menaces des fonctionnalités de produits intégrant l'IA, en déployant l'IA et l'automatisation pour étendre la portée de l'équipe.
  • Posséder des évaluations de sécurité de bout en bout pour des fonctionnalités et des services à haut risque, en travaillant directement avec les équipes d'ingénierie pour réduire les risques avant le déploiement.
  • Exploiter et faire évoluer les contrôles de numérisation de sécurité intégrés dans les pipelines GitLab de Smartsheet, en construisant des automatisations qui réduisent le fardeau des faux positifs.
  • This is a high-ownership, technically demanding role for an experienced application security engineer
  • If you're a security engineer who writes code to solve security problems, can read a production codebase to find what a scanner misses, and wants your work to matter beyond a ticket queue, we want to talk
  • Manual web application testing: Independent, hands-on validation of complex, multi-step authenticated vulnerabilities; you confirm what scanners flag and find what they miss
  • AI security: Hands-on experience securing AI-integrated applications (LLM systems, agentic workflows, model APIs) and demonstrated experience deploying AI and automation to scale security functions or extend team reach. You bring both skill sets
  • CI/CD pipeline security: Working knowledge of SAST, SCA, secrets, and IaC scanning in modern pipelines, with experience engaging teams on findings and improving signal quality
  • BS or MS in Computer Science, a related field, or equivalent industry experience
  • Bug bounty experience: Operator, active researcher, or both; direct experience with triage, severity calibration, and researcher communication
  • Security review depth: Threat modeling, architecture review, and code review for complex SaaS features; you produce findings engineering teams can act on and carry enough technical credibility to influence design decisions, not just document them
  • Experience: 8+ years in application security, with a track record of owning complex, multi-capability work in a product security or AppSec engineering role
  • Cloud security fundamentals: Working knowledge of AWS, GCP, or Azure sufficient to tie application-layer risk to the infrastructure it runs on; you understand where the application ends and the cloud begins
  • Software engineering foundation: Fluent in one or more modern languages (Java, Python, TypeScript/JavaScript, Go, Ruby, or equivalent); you identify security-relevant patterns without relying on tooling and write automation that others adopt
  • Legally eligible to work in the U.S. on an ongoing basis
  • Experience with agentic security, MCP security, or adversarial evaluation of autonomous AI systems
  • GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration
  • Active bug bounty researcher with published findings, CVE credits, or hall of fame recognition
  • Penetration testing program management experience: scope definition, vendor coordination, and finding validation with third-party testers

This is an external listing. JobSpring does not represent or verify the employer. Report this listing