Oneleet
Application Security Engineer
US/EU - Remote
Sponsorship not specifiedDetected 55 days ago
TypeScriptPythonGoFull-Stack DevelopmentLLMsCybersecuritySOC OperationsComplianceResearchCommunication
About the role
- ABOUT ONELEET Oneleet is one of the fastest-growing security and compliance platforms in history.
- Our team has decades of experience in security and compliance.
- If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you'll fit right in.
Responsibilities
- Own the integration, configuration, and output quality of security tooling that powers our platform
- Design rules, severity scoring, and triage flows that make findings actionable rather than overwhelming
- Build the security judgment layer on top of underlying tooling - context-aware prioritization and exploitability reasoning
- Partner with engineers on how findings are presented in the UI and how remediation flows work
- Work with PM and design on roadmap priorities, providing the security expertise that drives what to build next
- Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.
- Clear communicators - who own their ideas and follow through.
- Building on top of best-in-class open source tooling rather than reinventing from scratch
Requirements
- 5+ years of application security experience, with significant time shipping security products
- Experience in (and thrives in) a fast-moving, start-up engineering environment
- Strong programming skills in at least one of Go, Python, or TypeScript - this is a product engineering role with security depth, not security operations
- Hands-on experience tuning security tooling for production use - reducing false positives, building suppression logic, designing severity models
- Understanding of vulnerability research, CVE/CWE taxonomies, and exploit reasoning
- Has worked through what makes a security finding actually actionable vs. just technically true
- Excellent communication skills and comfort working directly with customers
- Pragmatic; knows how to build things fast without unnecessarily complicating things
Nice to have
- Prior experience shipping a security product at a vendor
- Contributions to open source security tooling
- Offensive security background or OSCP / similar certifications
- Hands-on experience with LLM agents, tool use, or autonomous AI systems
- Owning the security depth of a product from tooling integration to user-facing findings
- Working directly with security teams using the product and iterating on real-world feedback
- Joining a small, scrappy team where your security judgment shapes both the product and the company
Compensation
- 20 days PTO per year, plus 8 floating holiday
Benefits
- Comprehensive health & wellness benefits
- 20 days PTO per year, plus 8 floating holiday
- Competitive compensation & equity
- This posting reflects base salary only and does not include equity or benefits.
- We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.
- Within any range, individual compensation is determined by work location, skills and experience demonstrated through the interview process, and relevant education or training.
Company info
- make effective cybersecurity painless.
- We believe cybersecurity should empower, not burden.
- This belief unites our team and drives every decision we make.
- If you're ready to challenge the status quo and help shape the future of cybersecurity, we'd love to meet you.
- As an Application Security Engineer at Oneleet, you'll bring security depth to our product engineering teams as we expand our cybersecurity platform.
- You'll own the security judgment layer that sits between raw tooling output and what our customers actually see - deciding what to surface, what to suppress, and how to make findings genuinely useful rather than noisy.
- This is a hands-on, security-first engineering role at a Series A startup.
- You'll work closely with backend and fullstack engineers on how findings are stored, enriched, and presented, and you'll partner with product and design on what to build next.
- You'll be the security voice in product and engineering decisions, and you'll be empowered to push back when security judgment requires it.
- You'll work directly with customers - security teams using the platform day-to-day - to understand what they actually need, and iterate quickly based on their feedback.
- Engage with customers directly to understand how they use the platform and what's blocking adoption
- We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless.
- We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.
- Having just raised a $33 million Series A, we are rapidly growing in customers and employees.
Equal opportunity
- We are an equal opportunity employer.
Apply directly at Oneleet →Create a free account for alerts like thisView Oneleet immigration profile
This listing is sourced directly from Oneleet's careers page and normalized into a canonical job model.