Earth Is Our Runway
Shield AI Logo

Shield AI

Staff Application Security Engineer (R5949)

Posted An Hour Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
143K-214K Annually
Senior level
Remote
Hiring Remotely in USA
143K-214K Annually
Senior level
Build and lead a scalable application security and secure SDLC program across engineering teams. Establish policies, standards, tooling, vulnerability management, threat modeling, developer enablement, security champions, software supply-chain controls, and executive reporting. Partner with development, platform, DevOps, product, and leadership teams to integrate security into CI/CD, source control, build, release, and deployment workflows while supporting audits, advisories, incident response, and regulatory requirements.
The summary above was generated by AI
Shield AI is a venture-backed defense-tech company with the mission of protecting service members and civilians with intelligent systems. Its products include Hivemind autonomy software, V-BAT and X-BAT aircraft, and Aechelon simulation and synthetic reality technologies. With offices and facilities across the U.S., Europe, the Middle East, and Asia-Pacific, Shield AI’s technology actively supports operations worldwide. For more information, visit www.shield.ai. Follow Shield AI on LinkedInXInstagram, and YouTube. 

We are seeking a Staff Application Security Engineer to build and advance a scalable, developer-centered application security program. This role will establish company-wide secure software development lifecycle (SDLC) policy and standards, translate them into practical engineering practices, and partner directly with product, platform, and development teams to improve secure development and software supply-chain maturity.

The successful candidate combines technical application-security depth with the programmatic leadership to drive enterprise-wide improvement. You will help teams build, test, package, release, and maintain secure software while ensuring security controls are practical, measurable, and integrated into existing engineering workflows.

This is a Staff level individual-contributor role with significant influence across engineering, security, product, and technology leadership.

What you'll do:

    * Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.
    * Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.
    * Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.
    * Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.
    * Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.
    * Evaluate, implement, tune, and operationalize application-security tooling, including:* Static application security testing (SAST)
    * Dynamic application security testing (DAST)
    * Software composition analysis (SCA)
    * Secrets detection
    * Infrastructure-as-code security scanning
    * Container and image security scanning
    * API and cloud-native application security controls

    * Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.
    * Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.
    * Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.
    * Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.
    * Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.
    * Mature software supply-chain security practices, including:* Machine-readable software bills of materials (SBOMs)
    * Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications
    * Build and release provenance
    * Artifact, package, container-image, and binary signing
    * Artifact verification and trusted promotion processes
    * Secure artifact repositories and package registries
    * Approved dependency sources and package integrity verification
    * SLSA-aligned build integrity, provenance, and release controls

    * Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.
    * Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
    * Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.
    * Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.
    * Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.
    * Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.
    NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.

Required qualifications:

    * 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related field.
    * Demonstrated experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams.
    * Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.
    * Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices.
    * Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling.
    * Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
    * Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition.
    * Knowledge of common application-security risks, including authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.
    * Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.
    * Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.
    * Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable secure-development and supply-chain security frameworks.
    * Ability to read and assess production code and scripts in one or more modern programming languages.
    * Strong written and verbal communication skills, including the ability to explain technical risk and tradeoffs to developers, leaders, auditors, and nontechnical stakeholders.

Preferred qualifications:

    * Experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls.
    * Experience with VEX, CSAF, SBOM formats such as SPDX or CycloneDX, and component or vulnerability intelligence workflows.
    * Experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.
    * Experience with common source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.
    * Experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies.
    * Experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements.
    * Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance product environments.
    * Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.

#LI-KE1
#LC

Full-time regular employee offer package:
Pay within range listed + Bonus + Benefits + Equity
 
Temporary employee offer package:
Pay within range listed above + temporary benefits package (applicable after 60 days of employment)
 
Salary compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, licenses and certifications, and specific work location. All offers are contingent on a cleared background and possible reference check. Military fellows and part-time employees are not eligible for benefits. Please speak to your talent acquisition representative for more information.
 
###
 
Shield AI is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or Veteran status. If you have a disability or special need that requires accommodation, please let us know. 

Similar Jobs at Shield AI

An Hour Ago
Remote
USA
200K-300K Annually
Senior level
200K-300K Annually
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Own production operations for workplace AI platforms, including configuration, integrations, observability, secrets, access controls, model and prompt changes, benchmarking, and incident response. Translate technical findings into governance, risk, compliance, and training materials while collaborating with Security, Legal, HR, and business stakeholders. Investigate failures, implement mitigations, document root causes, and maintain reliable, secure AI services.
Top Skills: Access ControlAi/Llm PlatformsAlertingAPIsInfrastructure As CodeJSONLoggingMetricsMonitoring And ObservabilityPrompt EngineeringRpa/Workflow EnginesSecrets ManagementYaml
Yesterday
Remote
USA
76K-110K Annually
Mid level
76K-110K Annually
Mid level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Designs and produces proposal documents, presentations, graphics, infographics, and bid materials. Translates complex technical information into clear visual stories, maintains templates and design systems, coordinates document production and quality checks, tracks revisions and submission requirements, and supports final digital and print delivery. Collaborates with proposal managers, business development teams, and technical experts while improving production workflows and supporting customer-facing materials.
Top Skills: Adobe AcrobatAdobe Creative CloudAdobe IllustratorAdobe IndesignAdobe PhotoshopPdf
Yesterday
In-Office or Remote
Senior level
Senior level
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Develops and improves aerospace suppliers producing harness assemblies and electronic components. Leads supplier onboarding, new-product industrialization, process capability, quality, capacity, and delivery improvements across engineering teams and contract manufacturers. Applies PPAP, RCCA, fishbone analysis, process mapping, and 5S to resolve production challenges and scale manufacturing. Requires extensive supplier development experience and international travel up to 50%.
Top Skills: 5SFpc/Ffc AssembliesPpapRccaWire Harness Assemblies

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account