← Back to job listings
SM
Senior Security Engineer (Application Security)
Smartsheet · United States
About The Role
Join Smartsheet, a leading SaaS platform, as a Senior Security Engineer II in the Application Security team. In this role, you will leverage your expertise in securing AI-integrated systems and deploy AI and automation to drive risk visibility and reduction. You will conduct security reviews, deliver application security assessments, advance CI/CD pipeline security, and run bug bounty operations. This is a high-ownership, technically demanding role for an experienced application security engineer.
- Conduire des examens de sécurité et des modélisations de menaces des fonctionnalités de produits intégrant l'IA, en déployant l'IA et l'automatisation pour étendre la portée de l'équipe.
- Posséder des évaluations de sécurité de bout en bout pour des fonctionnalités et des services à haut risque, en travaillant directement avec les équipes d'ingénierie pour réduire les risques avant le déploiement.
- Exploiter et faire évoluer les contrôles de numérisation de sécurité intégrés dans les pipelines GitLab de Smartsheet, en construisant des automatisations qui réduisent le fardeau des faux positifs.
- This is a high-ownership, technically demanding role for an experienced application security engineer
- If you're a security engineer who writes code to solve security problems, can read a production codebase to find what a scanner misses, and wants your work to matter beyond a ticket queue, we want to talk
- Manual web application testing: Independent, hands-on validation of complex, multi-step authenticated vulnerabilities; you confirm what scanners flag and find what they miss
- AI security: Hands-on experience securing AI-integrated applications (LLM systems, agentic workflows, model APIs) and demonstrated experience deploying AI and automation to scale security functions or extend team reach. You bring both skill sets
- CI/CD pipeline security: Working knowledge of SAST, SCA, secrets, and IaC scanning in modern pipelines, with experience engaging teams on findings and improving signal quality
- BS or MS in Computer Science, a related field, or equivalent industry experience
- Bug bounty experience: Operator, active researcher, or both; direct experience with triage, severity calibration, and researcher communication
- Security review depth: Threat modeling, architecture review, and code review for complex SaaS features; you produce findings engineering teams can act on and carry enough technical credibility to influence design decisions, not just document them
- Experience: 8+ years in application security, with a track record of owning complex, multi-capability work in a product security or AppSec engineering role
- Cloud security fundamentals: Working knowledge of AWS, GCP, or Azure sufficient to tie application-layer risk to the infrastructure it runs on; you understand where the application ends and the cloud begins
- Software engineering foundation: Fluent in one or more modern languages (Java, Python, TypeScript/JavaScript, Go, Ruby, or equivalent); you identify security-relevant patterns without relying on tooling and write automation that others adopt
- Legally eligible to work in the U.S. on an ongoing basis
- Experience with agentic security, MCP security, or adversarial evaluation of autonomous AI systems
- GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration
- Active bug bounty researcher with published findings, CVE credits, or hall of fame recognition
- Penetration testing program management experience: scope definition, vendor coordination, and finding validation with third-party testers
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring