Apollo.io
Senior Application Security Engineer
Remote, Canada; Remote, United States · Senior
Sponsorship not specified$218k-$273kDetected 16 days ago
PythonRubyCode ReviewGCPLinuxOAuthCybersecurityPenetration TestingStakeholder ManagementHubSpotResearchCommunicationCollaborationMentoring
About the role
- The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo's secure software development lifecycle and reducing application risk across product, platform, and AI-powered features.
- This role blends deep code-level application security work with strong cross-functional partnership.
- It includes application security reviews, threat modeling, AppSec tooling, findings triage and remediation follow-through, external testing intake, and developer enablement.
Responsibilities
- Secure SDLC, design review, and threat modeling
- Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment.
- Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch.
- Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems.
- Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs.
- Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities.
- Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom.
- Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities.
- Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly.
- Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely.
Requirements
- Required Skills & Experience
Nice to have
- Experience supporting or leading security reviews for AI-native products, internal agents, or AI-assisted engineering workflows.
- Experience with security training, developer enablement, or security champions programs.
- Relevant security certifications are a plus.
- Example Success Outcomes
- Complete recurring application reviews or threat models for important systems and features.
- Increase engineering adoption of secure patterns, AppSec tooling, and security training.
- Reduce manual toil and improve AppSec signal quality through targeted automation and responsible use of AI-assisted workflows.
- life/AD&D/STD/LTD insurance
Compensation
- Owns meaningful AppSec goals over a semi-annual or annual horizon and independently identifies the right solutions to ambiguous, open-ended problems.
Benefits
- Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise.
Apply directly at Apollo.io →Create a free account for alerts like thisView Apollo.io immigration profile
This listing is sourced directly from Apollo.io's careers page and normalized into a canonical job model.