San Francisco, CAremote

Salary
$170,000–$200,000
Posted
Jul 16, 2026
Location
San Francisco, CA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A hands-on application security engineering role focused on building and running an AI-driven security program for a fintech platform that handles members' financial and tax data. Day-to-day work spans designing agentic pipelines for SAST, DAST, and dependency scanning integrated into CI/CD, leading threat modeling, driving vulnerability remediation end to end, and shipping framework-level fixes that eliminate whole vulnerability classes. Suits someone with deep appsec knowledge who is comfortable making targeted changes in a production Python/Django codebase and building with LLMs to automate security workflows.

Senior level · 4+ years · Remote · Full-time

Must have (7)
SASTDASTCI/CDSemgrep, Codeql or BanditOWASP ZAP or Burp SuiteLLMsPython
Nice to have (2)
DjangoAWS

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 2,500 people nationally plausibly meet what this posting asks for (information security analysts). range 730–3,700

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python51%CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The JD describes a hybrid role based in San Francisco, but the caller has declared this fully remote with a national candidate pool — metro has been left blank accordingly.

Semgrep, CodeQL, and Bandit are listed together as examples of SAST tooling under the requirements section with 'or equivalent'; Semgrep is used as the primary name with CodeQL and Bandit as alternatives.

OWASP ZAP and Burp Suite are listed as DAST tool examples under the requirements section; OWASP ZAP is primary with Burp Suite as an alternative.

LLMs/AI agents are firmly required — the JD gates on genuine hands-on experience building with them for security automation, stated in the 'What you'll bring' section.

Python and Django appear in a parenthetical stack note ('we run Python/Django on AWS') within the requirements section. Python is treated as a hard gate given the explicit expectation of making confident code changes in the production codebase; Django and AWS are treated as preferred since they appear as contextual stack color rather than explicit gates.

No compensation figures are provided in the posting.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗