Oneleet

Oneleet

Application Security Engineer

US/EU - Remote

Sponsorship not specifiedDetected 55 days ago
TypeScriptPythonGoFull-Stack DevelopmentLLMsCybersecuritySOC OperationsComplianceResearchCommunication

About the role

  • ABOUT ONELEET Oneleet is one of the fastest-growing security and compliance platforms in history.
  • Our team has decades of experience in security and compliance.
  • If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you'll fit right in.

Responsibilities

  • Own the integration, configuration, and output quality of security tooling that powers our platform
  • Design rules, severity scoring, and triage flows that make findings actionable rather than overwhelming
  • Build the security judgment layer on top of underlying tooling - context-aware prioritization and exploitability reasoning
  • Partner with engineers on how findings are presented in the UI and how remediation flows work
  • Work with PM and design on roadmap priorities, providing the security expertise that drives what to build next
  • Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry.
  • Clear communicators - who own their ideas and follow through.
  • Building on top of best-in-class open source tooling rather than reinventing from scratch

Requirements

  • 5+ years of application security experience, with significant time shipping security products
  • Experience in (and thrives in) a fast-moving, start-up engineering environment
  • Strong programming skills in at least one of Go, Python, or TypeScript - this is a product engineering role with security depth, not security operations
  • Hands-on experience tuning security tooling for production use - reducing false positives, building suppression logic, designing severity models
  • Understanding of vulnerability research, CVE/CWE taxonomies, and exploit reasoning
  • Has worked through what makes a security finding actually actionable vs. just technically true
  • Excellent communication skills and comfort working directly with customers
  • Pragmatic; knows how to build things fast without unnecessarily complicating things

Nice to have

  • Prior experience shipping a security product at a vendor
  • Contributions to open source security tooling
  • Offensive security background or OSCP / similar certifications
  • Hands-on experience with LLM agents, tool use, or autonomous AI systems
  • Owning the security depth of a product from tooling integration to user-facing findings
  • Working directly with security teams using the product and iterating on real-world feedback
  • Joining a small, scrappy team where your security judgment shapes both the product and the company

Compensation

  • 20 days PTO per year, plus 8 floating holiday

Benefits

  • Comprehensive health & wellness benefits
  • 20 days PTO per year, plus 8 floating holiday
  • Competitive compensation & equity
  • This posting reflects base salary only and does not include equity or benefits.
  • We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.
  • Within any range, individual compensation is determined by work location, skills and experience demonstrated through the interview process, and relevant education or training.

Company info

  • make effective cybersecurity painless.
  • We believe cybersecurity should empower, not burden.
  • This belief unites our team and drives every decision we make.
  • If you're ready to challenge the status quo and help shape the future of cybersecurity, we'd love to meet you.
  • As an Application Security Engineer at Oneleet, you'll bring security depth to our product engineering teams as we expand our cybersecurity platform.
  • You'll own the security judgment layer that sits between raw tooling output and what our customers actually see - deciding what to surface, what to suppress, and how to make findings genuinely useful rather than noisy.
  • This is a hands-on, security-first engineering role at a Series A startup.
  • You'll work closely with backend and fullstack engineers on how findings are stored, enriched, and presented, and you'll partner with product and design on what to build next.
  • You'll be the security voice in product and engineering decisions, and you'll be empowered to push back when security judgment requires it.
  • You'll work directly with customers - security teams using the platform day-to-day - to understand what they actually need, and iterate quickly based on their feedback.
  • Engage with customers directly to understand how they use the platform and what's blocking adoption
  • We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless.
  • We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners.
  • Having just raised a $33 million Series A, we are rapidly growing in customers and employees.

Equal opportunity

  • We are an equal opportunity employer.

This listing is sourced directly from Oneleet's careers page and normalized into a canonical job model.