Boston, MA

Salary
$230,000–$330,000
Posted
Aug 3, 2026
Location
Boston, MA
Last confirmed open
Sep 25, 2026

What this job asks for AI summary

This is an application security engineering role at an AI music startup, responsible for building and owning the AppSec practice from scratch. Day-to-day work spans threat modeling, secure SDLC tooling (SAST/DAST, secrets management, supply-chain security), hardening authentication and authorization, and securing AI/LLM-specific attack surfaces. The role suits a hands-on security engineer who can also write and ship production code alongside product and platform teams.

Senior level · 6+ years · Boston-Cambridge-Newton, MA-NH · Full-time

Pay in the description: $230,000–$330,000

Quick apply — this platform usually takes a CV and a few fields.

Must have (7)
Application Security · 6+ yrsThreat ModelingSAST or DASTSecure SDLCAuthentication & AuthorizationAPI SecurityAWS
Nice to have (1)
LLMs

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 110 people in the Boston-Cambridge-Newton, MA-NH area plausibly meet what this posting asks for (information security analysts). range 20–160

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Application Security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $139,553 (middle half $110,917–$180,330). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 5, 2026. It is a model, not a headcount.

Why we read it this way (6)

The title reads 'Senior / Staff' — the posting presents both levels simultaneously. The requirements (6+ years, building an AppSec practice, no explicit org-wide scope) best support Senior; Staff is not clearly warranted, so Senior is used for pool sizing.

The alternative occupation code 15-1252 is noted because the role explicitly requires writing and shipping production-quality code, not only security analysis — it sits meaningfully between the two occupations.

The posting lists three office locations (Cambridge MA, NYC, and LA are implied by the Fair Chance ordinance references) but does not name them explicitly; the CBSA is set to Boston/Cambridge as Suno's known headquarters.

LLMs and Generative AI appear only under 'Nice to have' and are marked preferred accordingly.

No degree requirement is stated anywhere in the posting.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Dependency / Supply-Chain Security, Secrets Management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗