Agility Robotics logo
Agility Robotics

We build robots made for work, engineered to work in nearly any environment, alongside people.

Staff Application Security Engineer

Application EngineerApplication EngineerFull TimeRemoteLeadTeam 201-500Since 2017H1B SponsorCompany SiteLinkedIn

Location

California + 2 moreAll locations: California | Oregon | Pennsylvania

Posted

2 days ago

Salary

$161K - $251K / year

Seniority

Lead

Job Description

Staff Application Security Engineer

Agility Robotics

• Security Development Lifecycle (SDLC) Integration: Drive the implementation of security practices throughout the entire software development process, from design review through deployment. • Application Security Testing: Perform offensive penetration testing and defensive (Blue Team) testing on web applications, internal services, and robot-side software to identify and remediate vulnerabilities. • Automation and Tooling: Implement and manage security tools, including Static Application Security Testing (SAST) or Dynamic Application Security Testing (DAST) or runtime vulnerability assessments, and Software Bill of Materials (SBOM) systems. Implementation of these systems using tools such as JFrog Artifactory, GitHub Advanced Security, Datadog, Wiz or Snyk. • Code Review and Governance: Define and enforce security policies for source code, including mandatory GitHub security practices and review procedures. • Vulnerability Management: Manage the lifecycle of identified vulnerabilities, prioritizing remediation efforts based on risk to the fleet, proprietary code, and cloud infrastructure. • Collaboration: Partner with development, platform, and infrastructure teams to ensure security requirements are met without hindering engineering velocity.

Job Requirements

  • 8+ years of dedicated, hands-on experience in Application Security (AppSec) engineering or a related Staff-level security role.
  • Demonstrated expertise in Application Security engineering with programming skills.
  • Proven hands-on experience implementing security controls in CI/CD pipelines and source control systems (e.g., GitHub, GitLab).
  • Experience with penetration testing, vulnerability scanning and offensive and defensive security (Red Team/Blue Team) practices.
  • Proficiency in at least one modern programming language (e.g., Python, Go, C++).
  • Strong understanding of security best practices for cloud-native, microservice, and distributed systems architecture.
  • Experience with cloud security such as AWS or GCP.
  • Kubernetes experience integrating security controls into K8s environments.
  • Experience leading and mentoring security engineers.

Benefits

  • 401(k) Plan: Includes a 6% company match.
  • Equity: Company stock options.
  • Insurance Coverage: 100% company-paid medical, dental, vision, and short/long-term disability insurance for employees.
  • Benefit Start Date: Eligible for benefits on your first day of employment.
  • Well-Being Support: Employee Assistance Program (EAP).
  • Time Off:
  • Exempt Employees: Flexible, unlimited PTO and 12 company holidays, including a winter shutdown.
  • Non-Exempt Employees: 10 vacation days, paid sick leave, and 12 company holidays, including a winter shutdown, annually.
  • On-Site Perks: Catered lunches four times a week and a variety of healthy snacks and refreshments at our Salem and Pittsburgh locations.
  • Parental Leave: Generous paid parental leave programs.
  • Work Environment: A culture that supports flexible work arrangements.
  • Growth Opportunities: Professional development and tuition reimbursement programs.
  • Relocation Assistance: Provided for eligible roles.
  • Annual Discretionary Bonus: Provided for eligible roles.

Related Categories

Related Job Pages

More Application Engineer Jobs

GovCIO logo

VistA Pharmacy Applications Release Verifier

GovCIO

GovCIO is a service-disabled-veteran-owned small business (SDVOSB) that offers technology services to improve business performance for government organizations.

Role Description GovCIO is seeking a VistA Pharmacy Applications Release Verifier (Remote/Part-Time) to join our Patient Care Services Product line, in the Office of Information Technology at the Department of Veterans Affairs. The candidate will support the release management and package verification of VistA-related patches using the National Patch Module (NPM) on FORUM. This position will be a fully remote within the United States with core hours of operation from Monday to Friday 8 AM to 5 PM ET. - Collaborate closely with development teams, Health Infrastructure and Systems Management (HISM) VistA Applications teams, Software Quality Assurance (SQA), and VHA Initial Operating Capability (IOC) test sites throughout the full patch lifecycle. - Ensure all requirements, validations, and release steps are executed according to VistA Patch Release standards. - Coordinate end-to-end VistA patch testing and release activities using the National Patch Module (NPM). - Perform Verifier responsibilities, including checklist execution, review validation, compliance date alignment, and patch status updates. - Manage release artifacts by moving builds, executables, and documentation to the National File Server as required. - Analyze defect incidents, reproduce issues, conduct assessments, and document findings for defect resolution. - Maintain Problem Incident updates throughout development, testing, and verification phases. - Evaluate enhancement requirements by reviewing user stories and validating expected functionality. - Create Patch Stubs following VistA Patch Template standards, including Packman and Host File formats. - Develop complete Patch Descriptions with accurate installation steps and required supporting documentation. - Upload KIDS Builds to NPM on FORUM and document progress in Problem Incidents. - Coordinate with other Verifiers or Functional Analysts when development overlaps across product areas. - Conduct technical preparation activities such as checksum verification and routine backups. - Update routines using approved VistA tools (KIDS Utilities, ^XINDEX) and submit Data Dictionary changes to the DBA. - Validate ICR usage, submit new or updated ICR requests, and coordinate HL7 messaging reviews for impacted components. - Support FDA impact reviews and assess external system impacts, engaging stakeholders as needed. - Assist developer unit testing, coordinate peer code reviews, and support SQA using the VistA SQA Checklist. - Prepare all required SQA and UAT distribution materials, including developer checklists, documentation, and versioned Host File Builds. Qualifications - Master's with 10 years (or commensurate experience) - Strong understanding of software development lifecycles (SDLC), Agile/SAFe, and CI/CD pipelines. - Proven experience coordinating complex, multiteam releases in enterprise or mission-critical environments. - Exceptional communication, facilitation, and stakeholder management skills. - Ability to manage multiple releases simultaneously with tight deadlines. - Strong analytical, organizational, and problem-solving skills. Requirements - Ability to obtain and maintain a Suitability/Public Trust clearance Preferred Skills and Experience - Experience working within the Department of Veterans Affairs (VA) or other federal healthcare environments. - Familiarity with NPM, KIDS Builds, HL7 messaging, Data Dictionary structures, and VistA architecture. - Experience with incident/problem management and structured testing methodologies. SAFe ITIL, PMP, or Agile certification(s). - Experience with automated testing, monitoring, and deployment tooling. - Strong understanding of risk, compliance, and audit requirements for production systems. Posted Salary Range USD $55.00 - USD $60.00 /Hr.

United States
$55 - $60 / hour

Senior Application Security Engineer

vCluster Labs

vCluster Labs is a venture-backed tech startup headquartered in San Francisco, California, with a distributed, remote-first team spanning eight time zones. Foun

Lead end-to-end security for products, perform deep-dive security reviews, manage vulnerability lifecycles, and integrate security checks into workflows to ensure a robust security posture in multi-tenant environments.

Bulgaria + 19 moreAll locations: Bulgaria | Croatia | Cyprus | Czechia | Egypt | Israel | Kenya | Lebanon | Luxembourg | Malta | Nigeria | Oman | Qatar | Romania | Saudi Arabia | Serbia | South Africa | United Arab Emirates | United Kingdom | Canada
True Anomaly logo

Senior Application Security Engineer

True Anomaly

Space was once the quietest place in the universe. Now, it's crowded, contested, and confrontational. We are True Anomaly: the only defense company focused exclusively on space defense. Founded in 2022 by ex-U.S. Space Force members, True Anomaly designs and builds advanced systems for space superiority: agile and powerful spacecraft platforms, mission software engineered for unmatched command and control, and payloads tailored for precision sensing and effects. True Anomaly is headquartered in Centennial, CO, with regional offices in Colorado Springs, CO, Long Beach, CA, and Washington, D.C. We are hiring and seeking exceptional talent to join True Anomaly, from any technical industry or background, to bring unique talents, perspective, and solutions. If you embrace complexity, lead instead of follow, showcase integrity over ego, take ownership for outcomes, and measure success by impact, we want to hear from you.

Full TimeRemoteTeam 250Since 2022

Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. OUR MISSION True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground. OUR VALUES - Be the offset. We create asymmetric advantages with creativity and ingenuity. - What would it take? We challenge assumptions to deliver ambitious results. - It’s the people. Our team is our competitive advantage and we are better together. YOUR MISSIONAs a Senior Application Security Engineer, you will be instrumental in implementing and auditing security controls for mission-critical space systems that must meet stringent government compliance requirements. You will work at the intersection of security engineering, compliance frameworks (NIST 800-171/800-53), and modern cloud-native architectures to ensure our satellite mission control software and flight systems meet Department of Defense security standards. You will design and implement application-level security controls including comprehensive audit logging, incident response capabilities, access controls, and security monitoring—all while working closely with product engineering teams to shift security to ensure optimal outcomes. If you thrive in a fast-paced environment where you can build security controls from the ground up and see the direct impact of your work on national security space operations, this mission is for you. This position requires the ability to obtain and maintain a security clearance. Responsibilities - Create security architecture documentation and operational security guides for government authorization processes - Drive vulnerability management program with defined SLAs for remediation (30/90/180 days by severity) - Perform security code reviews for Elixir, Python, C++, and JavaScript codebases - Collaborate in the triage and management of security automations using SAST (CodeQL, Semgrep), SCA (JFrog Xray), and DAST tools - Collaborate with engineering teams to address security findings and implement secure coding practices - Develop and deliver security training to software engineers and systems administrators across the organization - Create and manage incident response playbooks specific to application security events - Evaluate and integrate third-party security solutions to enhance overall security capabilities Qualifications: - 5+ years of experience in application security, product security, or security engineering - Hands-on experience implementing security controls for compliance frameworks such as NIST 800-171, NIST 800-53, FedRAMP, or CMMC - Strong software engineering skills with ability to write production-quality code in at least one language (Python, Rust, Elixir, C++, or similar) - Experience with cloud security (Azure preferred, AWS or GCP acceptable) - Solid understanding of secure architecture principles including: - Threat modeling and risk assessment - Authentication and authorization patterns (OAuth2, JWT, RBAC, ABAC) - Cryptography and key management - Defense-in-depth and Zero Trust principles - Proven ability to work collaboratively with engineering teams to implement security controls without blocking velocity - Eligible for DoD Secret or TS/SCI clearance Preferred Skills: - Active TS/SCI clearance or ability to obtain and maintain a security clearance - Direct experience with NIST 800-171 Rev 3 or NIST 800-53 implementation projects (gap analysis, control implementation, evidence collection) - Experience with Department of Defense Impact Levels (IL2/IL4/IL5/IL6) or STIGs (Secure Technical Implementation Guides) - Familiarity with Elixir/Erlang/Phoenix or other functional programming ecosystems (Scala, Haskell, F#, OCaml) - Experience with Azure Government Cloud or other FedRAMP-authorized cloud environments - Experience using Ghommit tool - Background in DevSecOps or Platform Security Engineering: - GitOps workflows and CI/CD security - Infrastructure as Code security (Terraform, Bicep, Pulumi) - Kubernetes security (Pod Security Standards, network policies, service mesh) - Experience with security incident response including detection engineering and SOAR integration - Familiarity with aerospace, defense, or other highly regulated industries (finance, healthcare, critical infrastructure) - Previous experience in startups or fast-paced environments with ability to build processes from scratch COMPENSATION - Base Salary: Long Beach - $150,000 to $205,000, Denver - $145,000 to $195,000, SF Bay Area - $165,000 to $225,000 - Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, location, and experience. ADDITIONAL REQUIREMENTS - Work Location—Successful candidates must be located near Denver, SF Bay Area, or Long Beach. While we observe a hybrid work environment, significant work must be done on site. #LI-Onsite - Work environment—the work environment; temperature, noise level, inside or outside, or other factors that will affect the person's working conditions while performing the job. - Physical demands—the physical demands of the job, including bending, sitting, lifting and driving. This position will be open until it is successfully filled. To submit your application, please follow the directions below. To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.

California + 1 moreAll locations: California | Colorado
$145K - $205K / year
NCH Corporation logo

Application Engineer

NCH Corporation

Established in 1919 and based in Irving, Texas, NCH Corporation is a privately held family business that provides commercial, industrial, and institutional maintenance products and

Role Description The Application Engineer, Supplemental Disinfection can be based anywhere in the US and will support our Chem-Aqua Supplemental Disinfection Division. This person is integral to the daily operation of the business and requires a motivated self-starter who can work independently and in a fast-paced environment. This position offers an exciting opportunity to lead a growing part of the business with a diverse set of job duties and a range of opportunities for career advancement. Position requires travel approx. 50% but up to 75%. Chem-Aqua has a culture that recognizes results, while embracing the importance of work/life balance. Responsibilities: - Support our Supplemental Disinfection Team. - Work with sales force, customers, engineering, and technical marketing group to develop, design, install, and service supplemental disinfection equipment systems. - Provide commissioning/startup services for supplemental disinfection equipment. - Support equipment in existing supplemental disinfection applications, including routine maintenance and telephone support for field reps. - Audit existing applications and confirm service expectations are being met. - Consult customers to determine appropriate water treatment and maintenance practices to minimize risks associated with Legionella and other waterborne pathogens. - Collaborate with technical marketing and engineering teams to improve processes, documentation, literature, and collateral material. - Other projects and administrative duties as assigned by manager. Qualifications - Familiarity with premise plumbing systems both potable and non-potable. - Experience with PLCs, control theories (proportional, integral, derivative, and their combinations), flow based control, sensor based control. - A Bachelor of Science with a GPA above 3.0. Focus on engineering, biology, or chemistry preferred. - Proficiency in Microsoft Power Point, Excel, Word, and Outlook. - Strong interpersonal skills and an affinity to working with an interactive team. - Great organizational skills, attention to detail, follow through, and ability to manage multiple projects at once. - A high level of professionalism and strong communication skills. - The ability to survey facilities, take detailed notes, and produce reports based on findings. - The ability to speak comfortably in front of large groups during training and education seminars. - A positive attitude, a commitment to client service and a willingness to support the office team with a variety of assignments. Benefits - Full suite of benefits, employee development and recognition programs. - Convenient location with a fitness facility and restaurant located within our campus. - Paid vacation and holiday leave. - Wellness initiatives (on-site fitness facility and cafeteria, treadmill conference room, planned activities). - Community involvement (volunteering, fundraisers, charity events, school sponsorships and donations). - Employee recognition programs (appreciation week, awards and ceremonies). - Personal and professional development and growth. - Tuition reimbursement. - Financial wellness (retirement options, 401K match, employee credit union). - Benefits package (medical, dental, vision, life, long and short-term disability).

United States