Application Security Engineer
Cerebras builds wafer-scale AI computing systems and a cloud inference platform for training, fine-tuning, and serving AI models.
About Cerebras Systems, Inc.
Cerebras Systems is an AI-infrastructure company founded in 2015. It sells rack-scale wafer-scale computing systems and provides cloud-based, API-accessible AI inference alongside on-premises deployments.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will own vulnerability management from discovery through remediation verification. You will investigate and prioritize findings, build automation, operate application-security tools, validate vulnerabilities, perform targeted security reviews, integrate controls into CI/CD, develop risk metrics, and support incident response for exploited vulnerabilities.
Requirements
- Application or product security fundamentals and vulnerability-management experience
- Knowledge of vulnerability classes and exploitation techniques across web applications, APIs, authentication, cloud services, containers, and software supply chains
- Ability to read code and collaborate with software engineers on remediation
- Experience with vulnerability scanning and application-security technologies
- Knowledge of CVSS, exploitability, asset criticality, internet exposure, compensating controls, and threat intelligence
- Ability to investigate security findings manually
- Ability to automate security workflows with Python, Go, or similar languages
- Experience integrating security tooling into CI/CD
- Experience with Linux, Git, containers, and cloud environments
- Security-risk communication skills
Responsibilities
- Improve vulnerability management across applications, dependencies, containers, operating systems, cloud infrastructure, and external services
- Use AI agents and security models for vulnerability discovery, analysis, testing, prioritization, and remediation
- Analyze vulnerabilities based on exploitability, exposure, assets, mitigations, and business impact
- Triage findings and drive risk-based remediation with engineering teams
- Build automation for vulnerability workflows and reporting
- Identify systemic vulnerability patterns and address root causes
- Operate SAST, SCA, secrets detection, container scanning, infrastructure scanning, and attack-surface monitoring
- Validate findings through technical investigation and hands-on testing
- Perform targeted application-security reviews and testing
- Integrate security controls into CI/CD and developer workflows
- Develop vulnerability and remediation metrics
- Support incident response for actively exploited vulnerabilities
