AlphaSense
Senior Application Security Engineer
Remote - United States · Senior
Sponsorship not specified$157k-$216kDetected 50 days ago
JavaScriptTypeScriptPythonJavaKotlinGitAWSKubernetesTerraformHelmCI/CDMachine LearningAgentic AICybersecurityPenetration TestingComplianceSupply ChainRecruitingResearchBurp Suite
About the role
- AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at high velocity.
- As a Senior AI Application Security Engineer, you will be a senior individual contributor at the center of that program.
- Operate and continuously tune the SAST, SCA, secrets-detection, and SBOM pipeline.
Responsibilities
- You will own the code and pull-request enforcement layer that every change flows through, whether authored by a human or an AI coding agent.
- This is a hands-on, build-it role.
- Design, ship, and harden the deterministic security gates that make AI-authored PRs auditably equivalent to human-authored ones.
- Drive findings to closure at the class level, fix a token-handling bug once at the platform layer and watch it propagate.
- Own how we secure AI-assisted development: Claude Code, Cursor, Copilot, MCP servers, agent-authored PRs, sub-agents handling rebases and CI fixes.
- Partner with harness engineering on agent scope declarations, agent identity registration, and the verification hooks that distinguish agent-initiated actions from human-initiated ones in the audit stream.
- Embed testable security acceptance criteria, agent scope declarations, and verification hooks into the PRD template so services declare their security posture at design time.
- Build, ship, own.
- Reports to the Director of Application Security, with a clear path to Staff / Tech Lead.
- We are committed to a work environment that supports, inspires, and respects all individuals.
Requirements
- 6+ years engineering experience, with 4+ in a dedicated AI Application Security / Product Security role at a SaaS or cloud-native company.
- You can read PRs fluently in at least two of Python, TypeScript / JavaScript, Java / Kotlin, or Go, and you are comfortable in Terraform, Helm, and Kubernetes manifests.
- Hands-on experience with agentic AI and MCP development.
- You have personally built with, integrated, or operated agentic tooling.
- Required
- 6+ years engineering experience, with 4+ in a dedicated AI Application Security / Product Security role at a SaaS or cloud-native company. Not a consulting / audit background.
- Development background, hands-on and recent. You write code, not just review it. You can read PRs fluently in at least two of Python, TypeScript / JavaScript, Java / Kotlin, or Go, and you are comfortable in Terraform, Helm, and Kubernetes manifests.
- Hands-on experience with agentic AI and MCP development. You have personally built with, integrated, or operated agentic tooling. Examples that qualify: built an MCP server
- integrated Claude Code, Cursor, or Copilot into a real engineering workflow under governance
- worked with autonomous coding agents or harnesses
- built or hardened an agent gateway
- shipped guardrails for prompt injection, jailbreak resistance, or output sanitization in production.
- Production operation of a SAST / SCA pipeline at scale, Snyk, Semgrep, GitHub Advanced Security, Checkmarx, Veracode, or equivalent, including rule authoring, false-positive tuning, and CI/CD integration.
- Demonstrated ownership of a threat modeling or developer security training program, founder or substantial contributor. You can describe the artifacts, the integration into the design process, and the metrics that proved it worked.
Nice to have
- Open-source contributions to a SAST / SCA tool, a security linter, an MCP server or framework, an agent harness, or a threat modeling tool.
- Experience shipping a deterministic compliance gate that an external auditor accepted as equivalent to human review.
- API security and DAST experience (Burp Suite, ZAP, Akto) and modern container / Kubernetes security (admission controllers, runtime protection, supply chain attestation).
- AWS security depth (IAM, KMS, GuardDuty, Security Hub, Organizations) and exposure to AI/ML production environments.
- Public writing or speaking on developer security, AI/agent security, or AppSec automation.
- Pre-IPO experience or familiarity with SOC 2 Type II, ISO 27001:2022, ISO 42001, SOX, GDPR.
- Certifications: OSWE, OSCP, CSSLP, AWS Security Specialty, or CISSP.
- Foundational hire, not a backfill.
Skills
- Threat model new AI features, agent gateway, MCP connector architecture, AI workflows in the research platform, and ship the controls.
- Scale the threat modeling framework. Pilot with the highest-risk teams, then make it standard for new features and architectural changes.
Compensation
- $157,000 - $216,000 USD
Benefits
- You may also be offered a performance-based bonus, equity, and a generous benefits program.
- Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients' own research content.
- Remote-first, high autonomy, competitive compensation, performance bonus, equity, and benefits.
Company info
- Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500.
- Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland.
Equal opportunity
- In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulation
Apply directly at AlphaSense →Create a free account for alerts like thisView AlphaSense immigration profile
This listing is sourced directly from AlphaSense's careers page and normalized into a canonical job model.