Allremote

Salary
$100,000–$300,000from the description
Posted
Jul 26, 2026
Location
All
Last confirmed open
Jul 28, 2026

What this job asks for AI summary

A product/application security engineering role at an early-stage AI cybersecurity startup, responsible for embedding security throughout the software development lifecycle — including threat modeling, secure code review, SAST/DAST, and supply-chain hardening. The hire will also build and automate security tooling, serve as an internal security SME, and help shape the company's security posture from the ground up as an early security hire.

Senior level · 5+ years · San Francisco-Oakland-Berkeley, CA · Full-time

Quick apply — this platform usually takes a CV and a few fields.

Must have (9)
application securitysecure SDLCthreat modelingSASTDASTcode reviewsupply chain securityCI/CDPython, Go or TypeScript
Nice to have (2)
AI/ML securitysecurity champions programs

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 110 people in the San Francisco-Oakland-Berkeley, CA area plausibly meet what this posting asks for (information security analysts). range 30–150

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python51%CI/CD45%application security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $165,879 (middle half $117,529–$206,125). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (5)

The role sits at the intersection of security analysis (15-1212) and hands-on software/security engineering (15-1252). The JD explicitly requires shipping code and automation, not just security analysis, making 15-1252 a credible alternative — but the primary framing is product/application security ownership, so 15-1212 was chosen.

Python, Go, and TypeScript are listed together as interchangeable examples of stack fluency ('e.g. Python, Go, Typescript, and/or similar'); they are captured as one skill with alternatives rather than separate hard gates.

The compensation range ($100K–$300K) is unusually wide; the posting notes it varies by location, level, and experience, and that equity and variable comp may also apply.

The role is listed as in-person in San Francisco and New York; remote is not offered.

AI/ML security and security-champions program experience appear under 'Bonus Points' and are marked as preferred accordingly.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗