730,610open jobs
43,655companies
102,906added this week
Browse all
Salary
$143k – $214k per year
Location
Remote (United States)
Seniority
Staff · 7+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 23, 2026. Shield AI scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Shield AI is an American defence technology company founded in 2015 that builds autonomy software and uncrewed aircraft for military missions. Its Hivemind autonomy stack lets aircraft fly, navigate and complete objectives without GPS, a remote pilot or a communications link, which matters in contested environments where those links are jammed. Headquartered in San Diego, California, the company fields the V-BAT vertical take-off aircraft with United States and allied forces, licenses Hivemind to other manufacturers and is developing the X-BAT jet for high-end missions.

We are seeking a Staff Application Security Engineer to build and advance a scalable, developer-centered application security program. This role will establish company-wide secure software development lifecycle (SDLC) policy and standards, translate them into practical engineering practices, and partner directly with product, platform, and development teams to improve secure development and software supply-chain maturity.

The successful candidate combines technical application-security depth with the programmatic leadership to drive enterprise-wide improvement. You will help teams build, test, package, release, and maintain secure software while ensuring security controls are practical, measurable, and integrated into existing engineering workflows.

This is a Staff level individual-contributor role with significant influence across engineering, security, product, and technology leadership.

What you'll do:

    * Establish, maintain, and continuously improve company-wide secure SDLC policies, standards, control objectives, procedures, and supporting evidence requirements.

    * Translate security policy into clear, achievable requirements for development, product, and platform teams without creating unnecessary delivery friction.

    * Assess the maturity of development teams, CI/CD pipelines, source-control practices, build environments, and release processes; define and lead practical improvement roadmaps.

    * Develop secure-development guidance, reference architectures, reusable patterns, security guardrails, exception processes, and developer enablement materials.

    * Partner directly with development teams to identify, triage, prioritize, remediate, and verify application-security findings.

    * Evaluate, implement, tune, and operationalize application-security tooling, including:* Static application security testing (SAST)

    * Dynamic application security testing (DAST)

    * Software composition analysis (SCA)

    * Secrets detection

    * Infrastructure-as-code security scanning

    * Container and image security scanning

    * API and cloud-native application security controls

    * Ensure security tooling produces actionable, appropriately prioritized findings and does not create unnecessary developer burden through excessive false positives.

    * Lead or facilitate threat modeling, security requirements definition, and secure design or architecture reviews for high-risk applications, integrations, and material changes.

    * Establish risk-based vulnerability management processes, including severity criteria, remediation service-level objectives, compensating controls, formal risk acceptance, escalation, and exception management.

    * Develop and maintain processes for identifying, tracking, and remediating vulnerable third-party, open-source, and transitive dependencies.

    * Establish open-source software governance, including component inventory, license identification, license review, approval workflows, and policy enforcement.

    * Mature software supply-chain security practices, including:* Machine-readable software bills of materials (SBOMs)

    * Vulnerability Exploitability eXchange (VEX) or equivalent vulnerability-status communications

    * Build and release provenance

    * Artifact, package, container-image, and binary signing

    * Artifact verification and trusted promotion processes

    * Secure artifact repositories and package registries

    * Approved dependency sources and package integrity verification

    * SLSA-aligned build integrity, provenance, and release controls

    * Partner with DevOps and platform engineering to secure CI/CD pipelines, including least-privilege access, protected branches, secure secret handling, hardened build environments, and release approvals.

    * Establish requirements for secure source-code repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.

    * Support application vulnerability intake, coordinated disclosure, customer-facing security advisories, CVE triage where applicable, and product-security incident response.

    * Create and lead a security champions program that provides developers with secure-coding guidance, training, office hours, practical tools, and a pathway for timely security engagement.

    * Develop executive-ready metrics and reporting on secure-SDLC adoption, AppSec risk, remediation performance, control coverage, software supply-chain integrity, and program maturity.

    * Support customer, regulatory, audit, and assurance activities related to secure-development and software supply-chain practices.

    NIST’s Secure Software Development Framework (SSDF), documented in NIST SP 800-218, provides a practical foundation for secure-development practices across organizational preparation, software protection, secure production, and vulnerability response.

Required qualifications:

    * 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a closely related field.

    * Demonstrated experience designing, implementing, or maturing a secure SDLC or application-security program across multiple engineering teams.

    * Strong working knowledge of secure coding practices, application-security testing, vulnerability management, software delivery, and DevSecOps principles.

    * Experience working directly with developers to explain findings, guide remediation, and improve secure-development practices.

    * Hands-on experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related application-security tooling.

    * Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.

    * Experience performing or facilitating threat modeling, security design review, architecture review, or security requirements definition.

    * Knowledge of common application-security risks, including authentication, authorization, API security, insecure deserialization, injection vulnerabilities, insecure dependency use, secrets exposure, and business-logic vulnerabilities.

    * Experience with software supply-chain security concepts, including SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and secure artifact management.

    * Experience with open-source software risk management, including vulnerable dependencies, transitive dependencies, license obligations, and governance processes.

    * Familiarity with NIST SP 800-218 / SSDF, OWASP SAMM, SLSA, or comparable secure-development and supply-chain security frameworks.

    * Ability to read and assess production code and scripts in one or more modern programming languages.

    * Strong written and verbal communication skills, including the ability to explain technical risk and tradeoffs to developers, leaders, auditors, and nontechnical stakeholders.

Preferred qualifications:

    * Experience implementing SLSA practices, signed software attestations, build provenance, hardened build systems, or release integrity controls.

    * Experience with VEX, CSAF, SBOM formats such as SPDX or CycloneDX, and component or vulnerability intelligence workflows.

    * Experience securing cloud-native applications, containers, Kubernetes, APIs, microservices, and infrastructure-as-code.

    * Experience with common source-control, CI/CD, cloud, artifact-management, package-management, or container-registry platforms.

    * Experience with tools such as Snyk, Checkmarx, Veracode, GitHub Advanced Security, GitLab security tools, Semgrep, SonarQube, OWASP ZAP, Burp Suite, Mend, Black Duck, or comparable technologies.

    * Experience with NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP, ISO 27001, SOC 2, or other regulated-environment requirements.

    * Experience supporting commercial software, government, defense, critical-infrastructure, or other high-assurance product environments.

    * Relevant certifications such as CSSLP, CISSP, GWAPT, GWEB, OSWE, GIAC, cloud-security certifications, or comparable credentials.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
730,610 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$59k – $120k per year (Estimated) • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Charlotte • Atlanta
DevOps
Azure
CI/CD
AWS
Cybersecurity
Least Privilege
Threat Modeling
Apply
$109k – $238k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Irving • Austin
Python
Rust
C++
AI/ML
AI Agents
Machine Learning
DevOps
GCP
Azure
AWS
Platform Engineering
Cybersecurity
MITRE ATT&CK
OWASP Top 10
Trend Micro
SIEM
Apply
In office • Full-Time
SQL
Mobile
App Center
DevOps
CI/CD
Management
Microsoft Teams
QA
Selenium
Postman
Apply
$81k – $193k per year (Estimated) • Remote/Hybrid • London
Databases
PostgreSQL
DynamoDB
Amazon Aurora
AI/ML
Claude
DevOps
GitHub Actions
CI/CD
AWS
AWS Fargate
AWS Lambda
Apply
Software Engineer 1 day ago
$95k – $233k per year (Estimated) • In office • Bachelor's Degree • Calgary
Python
C++
DevOps
CI/CD
Management
Agile
Scrum
Apply
$142k – $220k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Seattle
AI/ML
Edge AI
Chips/EDA
Cadence Allegro
Design
SolidWorks
Management
Agile
Apply
$75k – $222k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • London
Python
C++
Apply
$98k – $122k per year • In office • Full-Time • Bachelor's Degree • Seattle
AI/ML
Edge AI
Design
SolidWorks
Apply
$100k – $200k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • London
Python
C++
Apply
$99k – $207k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • London
Apply
See all jobs
This is one of many
730,610 more open roles from verified company boards, updated every day.