← Back to job listings
QU
Engineering Manager (Application Security)
Qualia · Austin, United States
About The Role
Join Qualia as an Engineering Manager for the Application Security team. In this role, you will lead the team in redesigning the modern AppSec function, leveraging AI to enhance security workflows. You will be responsible for scaling the team's output, embedding security earlier in the development lifecycle, and setting the security vision for the next two years. The ideal candidate will have 5+ years of experience in security or full-stack engineering, with a track record of shipping automation that changed team workflows.
- Lead and grow the Application Security team, coaching senior AppSec engineers, setting goals, and owning delivery against the security roadmap.
- Build the automated pen-testing program, standing up pipelines that run continuous, AI-assisted offensive testing against services, APIs, and web properties.
- Partner with the leadership team to set multi-quarter strategy across anomaly detection, threat modeling, and AI-augmented defense.
- 5+ years as a security or full-stack engineer working on production systems, with 2+ years managing a security or platform engineering team
- Track record of shipping automation that changed how a team worked - ideally including meaningful use of LLMs, agents, or ML in a security or engineering workflow
- Keen product sense and a bias toward measurable impact. You care whether the risk actually went down, not whether a ticket got closed
- Strong written communication. You can write the design doc, the post-mortem, and the board-ready summary - and you can tell a product engineer why their proposal needs to change without shutting down the conversation
- Comfort operating across the full security lifecycle: prevention, detection, response, and recovery
- Hands-on depth in application security: threat modeling, code review, and at least one offensive-security discipline (pen testing, red team)
- Experience in fintech, real estate tech, or another regulated, high-liability domain preferred
- Published research, CVEs, or conference talks in AppSec, offensive security, or AI security
- Background designing or operating anomaly-detection systems on production traffic, auth logs, or financial transactions
- Familiarity with the evolving landscape of AI-enabled offense (prompt injection, model abuse, agent exploitation) and defense
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring