Senior Application Security Engineer

4 weeks ago


Foster City CA, United States Zoox Full time

Foster City, CASoftware – Product Security /Full-time /HybridZoox is looking for an Application Security Engineer to join our Product Security team. Our team works on the cybersecurity of the Zoox robotaxi service. We guide and advise software engineering teams building our flagship product while aligning our efforts with company-wide cybersecurity goals and tooling.As a hands-on AppSec specialist, you will work closely with several software teams on topics both day-to-day (identifying code issues, offering guidance on a topic, reviewing new designs) and strategic (shaping the AppSec roadmap, keeping tabs on the ever-changing threat landscape, and building relationships).Beyond software development and cybersecurity knowledge, an ideal candidate would also possess the passion and skills necessary to implement our “shift-left” approach (having software teams participate in and own some of the security work, enabled by education and automation). ResponsibilitiesPerform application security reviews (design documents and security-relevant code) and threat modeling exercises. Prototype and implement security-focused features in code in partnership with engineering teams.Translate Zoox policies and standards into specific implementation guidance, including documentation, training, advice, and code level support.Work with other teams to make our application design patterns, shared libraries, and Software Development Lifecycle (SDLC)-related tooling secure-by-design.Improve the developer experience of “shift-left” application security-related systems and workflows. Train and support teams in using security tools on their own.Configure, integrate, modify, and develop off-the-shelf and custom security tools related to SDLC and application security. Triage and address issues reported by those tools. Report progress and identify interesting trends.Collaborate with feature teams and other cybersecurity teams across the company.Maintain awareness of new developments and technologies and suggest things to try as well as more substantial architectural changes as best practices evolve.Independently develop project briefs into actionable plans and carry them through.Contribute to and eventually own the application security part of our team’s long-term roadmap.Qualifications6+ years of experience across software engineering and cybersecurity. Deep understanding of common application security issues and their mitigations.3+ years of experience in a software engineering role, reaching fluency in a compiled, statically typed language and in an interpreted, dynamically typed language while developing production-grade services of substantial scope.Knowledge of high availability and large system design patterns, including microservice architectures, distributed systems, principles, and practices of working with data stores, build and release management, testing, and deployment.Persuasion, emotional intelligence, asynchronous communication skills, and relationship-building skills enable you to achieve complex goals on short deadlines with teams that do not report to you.Formal (threat model, attack graph, TARA) and informal ways to enumerate threats and evaluate risks, present them in the context of common cybersecurity frameworks, and then recommend multiple mitigation strategies.Bonus QualificationKnowledge of languages, patterns, and common issues in front-end applications, including single page applications (SPAs).Experience with AWS or other public clouds, DevOps/SRE practices, infrastructure-as-code tooling, and container-based service operation.CompensationThere are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. The salary range for this position is $186,000 to $265,000. A sign-on bonus may be offered as part of the compensation package. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position.Zoox also offers a comprehensive package of benefits including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance.About ZooxZoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We’re looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team.Follow us on LinkedInAccommodationsIf you need an accommodation to participate in the application or interview process please reach out to accommodations@zoox.com or your assigned recruiter.A Final Note:You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills.



  • Foster City, United States Zoox Full time

    Foster City, CA • Full-time Senior Application Security Engineer Zoox is looking for an Application Security Engineer to join our Product Security team. Our team works on the cybersecurity of the Zoox robotaxi service. We guide and advise software engineering teams building our flagship product while aligning our efforts with company-wide cybersecurity...


  • Los Angeles, CA, United States INTELLISWIFT INC Full time

    Job ID: 24-02366 Job Title: Senior Application Security Engineer Location: Woodland Hills, CA 91367 (Remote, southern CA preferred) Duration: 8 months Contract Type: W2 only Pay Rate: $105.17/Hour Scope Our team is looking for a Senior Application Security Engineer with extensive product security experience and deep expertise in...


  • Foster City, United States Zoox Full time

    As a Security Engineer - Detection and Response at Zoox, you will be part of a team responsible for the administration and operation of Zoox’s Enterprise SIEM, SOAR and EDR systems. You will focus on ongoing engineering and operations work related to those systems, continuously improving and looking for ways to better integrate them with our overall...


  • Foster City, United States Zoox Full time

    As a Security Engineer - Detection and Response at Zoox, you will be part of a team responsible for the administration and operation of Zoox’s Enterprise SIEM, SOAR and EDR systems. You will focus on ongoing engineering and operations work related to those systems, continuously improving and looking for ways to better integrate them with our overall...


  • Foster City, United States A Society Group Full time

    Join an exciting company which is adopting the latest technologies and is rapidly growing!We are seeking an experienced Cloud Security Engineer, who will be responsible for helping ensure the security of our customers, staff, systems, communications, and data.The Cloud Security Engineer will support the implementation, maintenance and upkeep cloud security...


  • Foster City, United States A Society Group, Inc. Full time

    Job DescriptionJob DescriptionJoin an exciting company which is adopting the latest technologies and is rapidly growing!We are seeking an experienced Cloud Security Engineer, who will be responsible for helping ensure the security of our customers, staff, systems, communications, and data. The Cloud Security Engineer will support the implementation,...


  • Redwood City, CA, United States Material Security Full time

    As a Senior Software Engineer at Material Security, you'll be part of an early, remote first, fast-growing team of experienced, world-class engineers, working to protect our users and their privacy (e.g inboxes from breaches, targeted phishing, fraud, and lateral account takeover). Specifically, our Data Protection team focuses on identifying, tracking,...


  • San Francisco, CA, United States Amazon Full time

    Do you thrive on the challenge of threat modeling and fortifying the defenses of AI/Gen AI and cloud systems? As a Senior Security Engineer (AppSec) on the AWS Gen AI security team, you will be entrusted with the security review and threat modeling of AWS Gen AI offerings. We conduct security reviews, penetration testing, build security automation, and...


  • Foster City, California, United States Gilead Sciences, Inc. Full time

    For Current Gilead Employees and Contractors:Please log onto your Internal Career Site $) to apply for this job.At Gilead, we're creating a healthier world for all people. For more than 35 years, we've tackled diseases such as HIV, viral hepatitis, COVID-19 and cancer – working relentlessly to develop therapies that help improve lives and to ensure access...


  • Foster City, United States tapwage Full time

    Zoox is looking for a Senior Infrastructure Security Engineer to join our Product Security team. The team works on the cybersecurity of the Zoox robotaxi service. We guide and advise software engineering teams building our flagship product while aligning our efforts with company-wide infrastructure architecture, shared tooling, and cybersecurity...


  • San Francisco, CA, United States Worldcoin.org Full time

    About the Company:Worldcoin () is an open-source protocol, supported by a global community of developers, individuals, economists and technologists committed to expanding participation in, and access to, the global economy. Its community is united around core beliefs in the inherent worth and equality of every individual, the right to personal privacy, and...


  • San Francisco, CA, United States Caldera Full time

    Senior Infrastructure Engineer, Security We’re looking for an incredible senior engineer to help us build the future of blockchain scalability. This is an ideal opportunity for an engineer who is already passionate about tackling problems in blockchain scalability, or looking to break into the blockchain engineering space. If you’re looking to work...


  • San Francisco, CA, United States SmithRx Full time

    SmithRx is a dynamic and rapidly growing Healthcare Tech startup that is venture-backed with a charter to transform the healthcare industry through innovative technology solutions. We are committed to revolutionizing the way healthcare is delivered and experienced, making it more efficient, accessible, and patient-centric. Our mission is to disrupt the...


  • Foster City, California, United States tapwage Full time

    Zoox is looking for a Senior Infrastructure Security Engineer to join our Product Security team. The team works on the cybersecurity of the Zoox robotaxi service. We guide and advise software engineering teams building our flagship product while aligning our efforts with company-wide infrastructure architecture, shared tooling, and cybersecurity...

  • AWS Security Engineer

    2 months ago


    Foster City, United States IntelliPro Group Inc. Full time

    Job DescriptionJob Description As a Cloud Security Engineer, you will: Manage best practice assessments and implementations within AWSReview existing AWS configurations and provide account and organization level hardening recommendations Participate in vulnerability management Improve network security within AWS: network ACLs, security groups, WAF, VPC...


  • Santa Monica, CA, United States The Chemical Engineer Full time

    Join our team as a Senior Process Engineer in Process Development, where you'll be responsible for supporting the development of a clinical manufacturing process of engineered T cells with patient-derived neo-antigen specific TCRs. Additionally, this role evaluates process and technology improvements, is critical to process understanding and process...


  • San Francisco, CA, United States Anthropic Limited Full time

    Anthropic is working on frontier AI research that has the potential to transform how humans and machines interact. As we rapidly advance foundational LLMs, application security is paramount. In this role, you will apply security patterns built for high-risk environments to safeguard model weights as we scale new capabilities. Working closely with software...


  • San Francisco, CA, United States CloudFlare Full time

    Lisbon or Remote Portugal About the Department The Identity and Access Management (IAM) team is dedicated to ensuring the secure and efficient management of user identities, access privileges, and authentication mechanisms across all company systems, applications, and data. Our mission is to safeguard the organization against unauthorized access, protect...


  • San Jose, CA, United States Industrialinnovationfund Full time

    Senior Security Engineer VIMAAN is looking to hire a talented senior security engineer to join our exceptional engineering team developing the next generation of information systems for the warehouse. You will work with cross-functional teams, plan, and prepare to block security threats, identify potential threats, and implement remediation. You will...


  • San Francisco, CA, United States SmithRx Full time

    Who We Are: SmithRx is a dynamic and rapidly growing Healthcare Tech startup that is venture-backed with a charter to transform the healthcare industry through innovative technology solutions. We are committed to revolutionizing the way healthcare is delivered and experienced, making it more efficient, accessible, and patient-centric. Our dedicated team of...