Information Security Engineer 4 at Lam Research
Fremont, CA
$92,000–$211,000from the description
Jun 30, 2026
Fremont, CA
Jul 21, 2026
What this job asks for AI summary
A mid-level application security role focused on supporting secure software development practices across internally built and AI-enabled applications. Day-to-day work spans threat modeling, code and design reviews, vulnerability assessment, penetration testing, and integrating security tooling (SAST, DAST, SCA) into CI/CD pipelines. The role also involves reviewing AI-specific security risks and working alongside engineering teams to embed security controls throughout the development lifecycle. Suits candidates with a background in application security, software engineering, or DevSecOps.
Mid level · 3+ years · San Jose-Sunnyvale-Santa Clara, CA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 80 people in the San Jose-Sunnyvale-Santa Clara, CA area plausibly meet what this posting asks for (information security analysts). range 25–120
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $179,993 (middle half $128,832–$221,179). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The salary range ($92,000–$211,000/year) is explicitly stated as applicable to the California San Francisco Bay Area only; the CBSA is mapped to San Jose-Sunnyvale-Santa Clara, CA (41940), which covers Lam Research's Fremont headquarters. The range is unusually wide and likely spans multiple internal levels.
The role is hybrid (On-site Flex or Virtual Flex), not fully remote — candidates must be able to work on-site at a Lam or customer/supplier location at least 1–3 days per week.
Degree requirement is marked None because the JD explicitly accepts 'equivalent practical experience' as an alternative to a Bachelor's degree.
SAST, DAST, and SCA appear together as interchangeable examples of 'one or more application security tools'; DAST and SCA are captured as alternatives to SAST rather than separate required skills, since the JD gates on experience with at least one of them.
Git and Bitbucket are listed as interchangeable examples; Jenkins, Azure DevOps, and Artifactory are similarly listed as interchangeable CI/CD platform examples — each group is collapsed into one skill with alternatives.
AI/ML security concepts (prompt injection, RAG, AI agents, generative AI, secure MLOps) appear only under Preferred Qualifications and are not extracted as hard gates.
Security certifications (Security+, CSSLP, CISSP, GIAC) are explicitly called 'preferred but not required' in the Preferred Qualifications section.
Seniority is assessed as Mid: 3+ years required, the role is framed as assisting and supporting senior engineers, and the scope is team-level contribution rather than independent ownership.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.