Staff Application Security Engineer
Shield AI is a U.S. defense-technology company developing mission-autonomy software and autonomous aircraft for military and allied operations.
Funding history
Investors
About Shield AI
Founded in 2015, Shield AI builds Hivemind autonomy software and V-BAT and X-BAT aircraft for operations in contested, GPS- and communications-denied environments. Its current site also presents Aechelon synthetic-reality simulation and Vision Systems detection and tracking products.
Skills
About the Role
You will establish and improve secure SDLC policies, standards, and engineering practices. You will work with developers to assess security maturity, integrate security tooling into delivery workflows, address vulnerabilities, secure the software supply chain, lead threat modeling, and report program risk and progress.
Requirements
- 7+ years of experience in application security, product security, DevSecOps, secure software engineering, cybersecurity engineering, or a related field.
- Experience designing, implementing, or maturing secure SDLC or application-security programs across multiple engineering teams.
- Knowledge of secure coding, application-security testing, vulnerability management, software delivery, and DevSecOps.
- Experience with SAST, DAST, SCA, dependency vulnerability management, secrets scanning, and related tooling.
- Experience integrating security controls into source-control, CI/CD, build, release, and deployment workflows.
- Experience with threat modeling, security design review, architecture review, or security requirements definition.
- Knowledge of application-security risks including authentication, authorization, API security, insecure deserialization, injection, dependency risks, secrets exposure, and business-logic vulnerabilities.
- Experience with software supply-chain security, SBOMs, dependency provenance, build integrity, artifact signing, release attestations, and artifact management.
- Experience with open-source software risk management, including dependency, license, and governance processes.
- Familiarity with NIST SP 800-218, SSDF, OWASP SAMM, SLSA, or comparable frameworks.
- Ability to read and assess production code and scripts in modern programming languages.
- Strong written and verbal communication skills.
Responsibilities
- Establish and improve secure SDLC policies, standards, procedures, and evidence requirements.
- Translate security policy into practical requirements for development, product, and platform teams.
- Assess development, CI/CD, source-control, build, and release maturity and lead improvement roadmaps.
- Develop secure-development guidance, reference architectures, guardrails, exception processes, and enablement materials.
- Identify, triage, prioritize, remediate, and verify application-security findings with development teams.
- Evaluate and operationalize SAST, DAST, SCA, secrets detection, infrastructure-as-code scanning, container scanning, and API security tooling.
- Lead threat modeling, security requirements definition, and secure architecture reviews.
- Establish risk-based vulnerability management and open-source software governance processes.
- Mature software supply-chain security practices, including SBOMs, provenance, signing, verification, and trusted artifact promotion.
- Secure CI/CD pipelines, source repositories, build systems, dependency registries, artifact repositories, and deployment pipelines.
- Support vulnerability intake, coordinated disclosure, security advisories, CVE triage, and product-security incident response.
- Lead a security champions program and develop executive-ready security metrics and reporting.
- Support customer, regulatory, audit, and assurance activities.
Benefits
- Bonus
- Equity
