Reltio

Reltio

Staff Application Security Engineer

United States · Staff+

Sponsorship not specified$114k-$240kDetected 7 days ago
JavaScriptJavaC#Node.jsSpringAWSGCPAzureCI/CDJenkinsDevOpsAPI DevelopmentMachine LearningLLMsAgentic AICybersecurityPenetration TestingComplianceSAPIntellectual PropertyAPI TestingLeadershipCommunicationCollaboration

About the role

  • Security Architecture & Technical Leadership
  • Influence engineering architecture and roadmap decisions without direct authority, driving risk-based consensus across teams.
  • Mentor and uplevel application security engineers and development teams, raising the secure-coding maturity of the broader organization.

Responsibilities

  • Serve as the senior application security subject matter expert, providing guidance on industry best practices, secure design patterns, and defense-in-depth strategies for the product security architecture.
  • Embed security throughout the SDLC, from design through deployment, and define secure coding standards and best practices adopted across teams.
  • Drive shift-left initiatives by providing guidance, tooling, paved-road patterns, and remediation support that enable engineers to build securely from the outset.
  • Design and implement security controls within CI/CD pipelines, enabling automated security testing and vulnerability detection at scale.
  • Operationalize SAST, SCA, DAST, and secrets scanning as policy-driven, low-friction gates; partner with release management on secure deployment checks and policy compliance.
  • Lead threat modeling sessions for complex, high-impact systems to identify and mitigate security risks early in design and architecture phases.
  • Perform technical risk assessments of new technology and ensure solutions meet secure architecture designs; assess, measure, and clearly communicate risk impact to stakeholders.
  • Analyze and validate remediation of application security findings from SAST, SCA, DAST, API testing, penetration tests, and manual assessments.
  • Drive risk-based prioritization of fixes, reduce false positives, and provide clear, actionable remediation guidance with proper pre-release validation.
  • Partner with engineering to ensure secure API design and implementation; identify and mitigate authentication/authorization issues, data exposure, rate-limiting gaps, and OWASP API Top 10 risks.

Requirements

  • 8+ years of experience in application security or software development, including significant time in a cloud-native or SaaS environment.

Nice to have

  • Hands-on experience securing LLM applications and multi-agent systems, including agentic guardrail frameworks (e.g., NeMo Guardrails, AWS Bedrock Guardrails) and MCP gateway/tool security.
  • Experience with commercial AppSec/SCA platforms such as Wiz Code, Veracode, Checkmarx, Cycode, or SonarQube.
  • Experience with industry frameworks such as SOC 2, HITRUST, or ISO 27001, and supporting audit/customer-assurance processes.
  • Applying ML/AI techniques to enhance security detection, anomaly identification, and automated risk prioritization.
  • Relevant security and cloud certifications.
  • We rely on market indicators to determine compensation and your specific job family, background, skills, and experience to get it right.
  • Overall Market Range
  • Reltio is proud to be an equal opportunity workplace.

Compensation

  • At Reltio, we carefully consider a wide range of compensation factors to determine your personal top of market.

Benefits

  • Helps to define and drive the overall application/product security architecture, vision, strategy, and roadmap across Reltio's platform and services.

Visa & Work Authorization

  • al employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status

This listing is sourced directly from Reltio's careers page and normalized into a canonical job model.