Staff Application Security Engineer
Reltio
$114,000–$240,000
Jul 14, 2026
—
Jul 21, 2026
What this job asks for AI summary
A senior individual contributor role focused on securing a cloud-native SaaS platform end to end — from embedding security into the software development lifecycle and CI/CD pipelines, to leading threat modeling, API security, and vulnerability management. The position also covers emerging territory in AI and agentic system security, including prompt injection defenses and model context protocol standards. It suits an experienced application security engineer comfortable shaping architecture and mentoring teams without holding direct management authority.
Staff level · 8+ years · Remote · Full-time
Pay in the description: $114,000–$240,000
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 740 people nationally plausibly meet what this posting asks for (information security analysts). range 150–1,100
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (11)
SOC code is a medium-confidence call: the role is deeply application-security focused (15-1212) but also requires hands-on secure coding, code review, and CI/CD pipeline engineering work that overlaps with 15-1252 Software Developers.
Location is not specified in the posting; Reltio is a distributed-workforce company and the role appears fully remote.
The 'Staff' title is used explicitly in the job title and the role is framed as a senior individual contributor setting cross-team technical direction — consistent with Staff-level seniority.
AWS, GCP, and Azure are listed together as a single requirement ('AWS, GCP, and/or Azure'); AWS is used as the primary name with GCP and Azure as alternatives.
Jenkins is listed as an example CI/CD tool ('e.g., Jenkins, ArgoCD, or similar'); ArgoCD is captured as an alternative. The requirement is for CI/CD pipeline security experience broadly, not Jenkins specifically.
Wiz is listed as preferred within the required skills section ('with Wiz preferred (other AppSec tools acceptable)') — because it appears in the hard-requirements block with firm language, it is treated as a required skill; the 'preferred' qualifier signals Wiz specifically is the desired tool but other AppSec platforms are acceptable substitutes.
AI security, LLM guardrails, and MCP security appear in the required skills block and are treated as hard gates; the more specific agentic guardrail frameworks (NeMo, AWS Bedrock Guardrails) appear only under 'Nice to Have'.
The compensation range ($114,000–$240,000/year) is unusually wide, likely reflecting geographic variation across a distributed/remote workforce.
No degree requirement is stated anywhere in the posting.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): OWASP API Top 10.
This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.