Job Closed
This listing is no longer active.
Webflow is the way to design, build, and launch powerful websites visually — without coding.
Staff Application Security Engineer
Location
California
Posted
133 days ago
Salary
$164K - $247K / year
Seniority
Lead
Job Description
Staff Application Security Engineer
Webflow
• Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem. • Bring security best practices to the software development lifecycle. • Champion security standards while balancing business strategies and requirements. • Support Webflow’s security compliance frameworks • Find security vulnerabilities through grey-box techniques • Propose solutions at the architecture and code level. • Contribute code and architecture improvements to enable security within Webflow’s application. • Cross-train entry and mid-level application security engineers.
Job Requirements
- BA/BS degree or equivalent experience
- 7+ years of application security experience
- Hands-on software development experience
- Technical authority in securing high-complexity, large-scale applications
- Deep expertise in secure software design, secure coding, and modern web application security
- Proven ability to identify security design flaws and complex business-logic vulnerabilities
- Experience leading threat modeling efforts
- Conduct and oversee advanced penetration testing
- Manage third-party pentests
- Designed, implemented, and evolved software supply chain security programs
- Owned or led bug bounty programs and major security tooling initiatives
- Implemented and improved Secure Development Lifecycle (SDLC) processes at scale
- Driven multi-quarter application security roadmaps and complex security programs
- Led security initiatives within large-scale solutions
- Experience using and building security solutions that leverage agentic AI
- Participated in and led response efforts for application security incidents
- Actively mentor and elevate other application security engineers
- Passion for security and continuous learning
- Ability to explain complex security concepts clearly.
Benefits
- Ownership in what you help build.
- Health coverage that actually covers you.
- Support for every stage of family life.
- Time off that’s actually off.
- Wellness for the whole you.
- Invest in your future.
- Monthly stipends that flex with your life.
- Bonus for building together.
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
Staff Application Security Engineer
ThumbtackWe help people care for their home from top to bottom — and empower small businesses nationwide to grow.
• Own the long-term technical direction for application security across Thumbtack • Lead large, cross-functional security initiatives from problem definition through delivery • Design secure architectures and implement shared security tooling • Partner with teams to prioritize security investments based on risk and impact • Mentor engineers and drive organization-wide improvements in application security
• Develop and maintain high-quality VOIP applications that meet customer needs, focusing on reliability, performance, and scalability. • Integrate VOIP solutions with third-party systems, ensuring seamless communication between internal and external platforms. • Provide support for complex VOIP issues, including system failures, call quality problems, and application errors. Work to quickly diagnose and resolve issues. • Work closely with cross-functional teams, including engineering, product management, and operations, to ensure seamless deployment and operation of VOIP applications. • Test new VOIP features, products, and services, ensuring they meet quality standards before deployment. • Create and maintain technical documentation for VOIP applications, including system architecture, troubleshooting guides, and integration processes. • Continuously monitor and optimize VOIP applications to improve performance, scalability, and user experience. • Ensure VOIP applications meet security standards and compliance requirements. • Assist internal and external teams with troubleshooting, providing solutions, and offering expert guidance on VOIP-related issues. • Stay current with emerging VOIP technologies and trends, contributing to the development of new features and improvements to existing applications.
• Develop and prepare technical solutions and quotation proposals for new equipment • Respond to customer inquiries for new equipment • Define the Elliott scope of supply • Complete requisition forms for major purchased auxiliaries • Review customer and industry standard specifications • Create proposals including data sheets, scope, performance curves, pricing, and delivery • Participate in bid clarification meetings with Sales/customer • Work with Sales/Management to adjust scope/delivery/price as needed • Transfer data to Project Engineering / Project Management after an order is received • Develop standards, repeatable procedures and calculations
Application Security Engineer – Public Trust/Secret Clearance
TOMORROW HIRETOMORROW HIRE is revolutionizing the staffing industry by integrating advanced AI technology with deep human expertise.
• Support Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and IDE Plug-in environments using Veracode and Burp Suite. • Design and implement enterprise-wide security controls to secure applications, systems, networks, or infrastructure services. • Secure enterprise web applications, with a focus on mitigating OWASP Top 10 risks, CVSS scoring, CWE, WASC, and SANS Top 25 vulnerabilities. • Integrate security practices into development workflows using IDEs such as Eclipse, JDeveloper (including pipeline development), or Visual Studio. • Perform application security testing and automation using tools such as OWASP ZAP, Burp Proxy, Selenium, and Interactive Application Security Testing (IAST) capabilities. • Write and maintain bash scripts to support security automation, testing, and troubleshooting tasks. • Participate in vulnerability discovery, triage, and remediation processes, including crowdsourced security programs via platforms like HackerOne. • Work in Linux or UNIX environments, including navigating file systems and troubleshooting basic website connectivity and security issues. • Ensure applications and security practices align with federal compliance standards, including NIST 800-53, FIPS, or FedRAMP.



