Skip to main content
Back to jobs

Senior Software Engineer, Application Security

External
handshake logoHandshake ยท San Francisco, CA
$176Kโ€“$220K/yrFull-timeOn-site3w ago
Application SecurityCloud SecurityGCPOWASPThreat ModelingTypeScript
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

As a Senior Application Security Engineer, you'll play a critical role in protecting Handshake's users and their data. You'll work closely with our engineering, platform, and cloud teams to make the secure way the easy way and embed security directly into how software gets designed, written, and shipped. This role is on our Cloud Security squad on our Infra & Platform team and is an engineering forward role. You'll be building systems, tools, and automation that make secure development the default. You'll bring a modern, opinionated perspective on how application security should work in a cloud-native, AI-enabled environment.

Responsibilities

  • Own and grow key areas of our Secure Software Development Lifecycle (SDLC) like threat modeling, security reviews, and vulnerability management.
  • Work collaboratively with and be a trusted partner for engineering teams.
  • Eliminate whole classes of vulnerabilities by building secure by default libraries and tools into our platform.
  • Raise the bar for security awareness by teaching others and sharing your knowledge
  • Design and build developer facing tooling to help engineers identify and fix security issues before they make it to production.
  • Scale your impact and security knowledge by teaching others, automating processes, and leveraging AI and agentic tooling.
  • Balance security and speed by using your judgement and expertise to add the right amount of security to our SDLC.
  • Help respond to potential security incidents as a member of the security on-call rotation.

Requirements

  • A builder mindset and experience working on large codebases and safely shipping code to production.
  • Strong understanding of common application security risks (OWASP Top 10) and how to mitigate them.
  • A pragmatic and empathetic approach to security controls that favors guidance over blocking and influence over mandates.
  • Strong communication skills and the ability to communicate security risks and tradeoffs to both technical and non-technical audiences.
  • Experience with threat modeling and risk assessments.
  • Familiarity with securing and running software in a major cloud provider.
  • Curiosity and a desire to use AI and agenting tooling to scale your and the security team's impact.
  • Bonus Points
  • Experience working in Google Cloud (GCP)
  • Experience writing production code in the most popular languages at Handshake: Ruby, Typescript and Go.
  • Experience building agentic systems to solve security problems.
  • Why This Role
  • If you care about building systems (not just processes), enjoy working closely with engineers, and want to rethink what modern application security looks like, we'd love to hear from you.

Benefits

Handshake delivers benefits that help you feel supported-and thrive at work and in life.The below benefits are for full-time US employees.๐ŸŽฏ Ownership: Equity in a fast-growing company๐Ÿ’ฐ Financial Wellness: 401(k) match, competitive compensation, financial coaching๐Ÿผ Family Support: Paid parental leave, fertility benefits, parental coaching๐Ÿ’ Wellbeing: Medical, dental, and vision, mental health support, wellness stipend๐Ÿ“š Growth: Learning stipend, ongoing development๐Ÿ’ป Remote & Office: Internet, commuting, and free lunch/gym in our SF office๐Ÿ Time Off: Flexible PTO, 15 holidays + 2 flexHealth insuranceDental insuranceVision insurance401(k)Paid time offRemote work optionsFlexible scheduleEquity / stock optionsPerformance bonusParental leave

Additional Information

About Handshake Handshake was founded on a simple belief that everyone deserves a path to a great career, regardless of where they went to school or who they know. Today, we power 25 million job seekers, 1 million+ employers, and 1,600 educational institutions. In 2025, we started Handshake AI and built the fastest-growing AI data business in history. We work directly with frontier AI lab researchers to create evaluations, publish benchmarks, and push the boundary of data. We've grown from $0 to ~$1B run rate and pay ~$60M to over 30K individuals every month. Why join Handshake now: Shape how every career evolves in the AI economy, at global scale, with impact your friends, family and peers can see and feel Partner hand-in-hand with world-class AI labs, Fortune 500 partners and the world's top educational institutions Work together with engineers, scientists, operators, and more from Palantir, Meta, Scale AI, and former YC founders Build a massive, fast-growing business with billions in revenue Senior Application Security Engineer At Handshake, we believe security should be built into the product, not layered on after the fact. We're looking for a Senior Application Security Engineer who's excited to shape how security shows up in the developer experience, and enable our engineering teams to ship secure code without compromising on velocity.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at handshake? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect