UniUni

UniUni

Staff Application Security Engineer

Remote (United States) · Staff+

Sponsorship not specifiedDetected 18 days ago
Code ReviewAWSKubernetesTerraformCI/CDLLMsCybersecurityPenetration TestingComplianceSupply ChainLogisticsMentoring

About the role

  • We are hiring a Application Security Engineer to be the senior technical anchor for product and platform security at UniUni.
  • You will spend your time shoulder-to-shoulder with engineering, not adjacent to it.
  • You will set standards that scale, but you will also dig into real systems to find real problems and ship real fixes.

Responsibilities

  • Application Security Lead threat modeling on new and existing services, focusing on the systems where the risk is real and the architecture is in motion.
  • Run our secure code review program, including the design of review playbooks, the hardest reviews yourself, and coaching engineers to catch issues earlier.
  • Own the third-party penetration testing program in partnership with the ISO, from scoping through findings triage and fix verification.
  • Drive standards for authentication, authorization, session management, and API security across our products, and engineer the hard parts yourself when needed.
  • Platform Security and DevSecOps Embed security controls into our CI/CD pipelines so the secure path is the default path: pre-commit checks, build-time scans, signed artifacts, and policy-as-code gates.
  • Codify infrastructure security baselines as IaC and policy (e.g., OPA/Conftest, AWS SCPs, Terraform guardrails) and own the rollout across the platform.
  • Partner with the platform team on identity-aware access to infrastructure, including non-human identities, short-lived credentials, and privileged access patterns.
  • Product Security Engineer enterprise SSO (SAML 2.0 and OpenID Connect) into customer-facing products in support of contractual security commitments to enterprise shippers.
  • Drive secure-by-default patterns for data handling in our products, including encryption, key management, and access controls for customer and operational data.
  • Across All of It Triage and lead response to application and platform security incidents, including root cause analysis and durable fixes.

Nice to have

  • Experience in logistics, supply chain, marketplaces, or other high-volume transactional businesses.
  • Background contributing to or maintaining open source security tooling.
  • Offensive security background (CTFs, bug bounty, red team) that informs how you think about defense.
  • Experience hardening LLM-integrated or AI-powered features in production.
  • Why This Role This is a senior IC role with real scope.
  • You will set standards that the engineering organization actually adopts because you will have built them, shipped them, and proved they work.
  • Harden our cloud workloads on AWS, including container and Kubernetes security, secrets management, and runtime protections.
  • Set the technical direction for API security, including authentication, authorization, rate limiting, abuse prevention, and tenant isolation.

Skills

  • Our technology is cloud-native on AWS.
  • Operate and tune our AppSec tooling stack across SAST, DAST, SCA, and secrets scanning, keeping signal high and noise low.
  • Platform Security and DevSecOps Embed security controls into our

This listing is sourced directly from UniUni's careers page and normalized into a canonical job model.