UniUni
Staff Application Security Engineer
Remote (United States) · Staff+
Sponsorship not specifiedDetected 18 days ago
Code ReviewAWSKubernetesTerraformCI/CDLLMsCybersecurityPenetration TestingComplianceSupply ChainLogisticsMentoring
About the role
- We are hiring a Application Security Engineer to be the senior technical anchor for product and platform security at UniUni.
- You will spend your time shoulder-to-shoulder with engineering, not adjacent to it.
- You will set standards that scale, but you will also dig into real systems to find real problems and ship real fixes.
Responsibilities
- Application Security Lead threat modeling on new and existing services, focusing on the systems where the risk is real and the architecture is in motion.
- Run our secure code review program, including the design of review playbooks, the hardest reviews yourself, and coaching engineers to catch issues earlier.
- Own the third-party penetration testing program in partnership with the ISO, from scoping through findings triage and fix verification.
- Drive standards for authentication, authorization, session management, and API security across our products, and engineer the hard parts yourself when needed.
- Platform Security and DevSecOps Embed security controls into our CI/CD pipelines so the secure path is the default path: pre-commit checks, build-time scans, signed artifacts, and policy-as-code gates.
- Codify infrastructure security baselines as IaC and policy (e.g., OPA/Conftest, AWS SCPs, Terraform guardrails) and own the rollout across the platform.
- Partner with the platform team on identity-aware access to infrastructure, including non-human identities, short-lived credentials, and privileged access patterns.
- Product Security Engineer enterprise SSO (SAML 2.0 and OpenID Connect) into customer-facing products in support of contractual security commitments to enterprise shippers.
- Drive secure-by-default patterns for data handling in our products, including encryption, key management, and access controls for customer and operational data.
- Across All of It Triage and lead response to application and platform security incidents, including root cause analysis and durable fixes.
Nice to have
- Experience in logistics, supply chain, marketplaces, or other high-volume transactional businesses.
- Background contributing to or maintaining open source security tooling.
- Offensive security background (CTFs, bug bounty, red team) that informs how you think about defense.
- Experience hardening LLM-integrated or AI-powered features in production.
- Why This Role This is a senior IC role with real scope.
- You will set standards that the engineering organization actually adopts because you will have built them, shipped them, and proved they work.
- Harden our cloud workloads on AWS, including container and Kubernetes security, secrets management, and runtime protections.
- Set the technical direction for API security, including authentication, authorization, rate limiting, abuse prevention, and tenant isolation.
Skills
- Our technology is cloud-native on AWS.
- Operate and tune our AppSec tooling stack across SAST, DAST, SCA, and secrets scanning, keeping signal high and noise low.
- Platform Security and DevSecOps Embed security controls into our
This listing is sourced directly from UniUni's careers page and normalized into a canonical job model.