Onebrief Logo

Onebrief

Senior Application Security Engineer

Sorry, this job was removed at 10:19 a.m. (PST) on Thursday, Feb 26, 2026
Remote
Hiring Remotely in USA
Remote
Hiring Remotely in USA

Similar Jobs at Onebrief

7 Days Ago
Remote
United States
180K-200K Annually
Senior level
180K-200K Annually
Senior level
Software • Defense
Own and improve Onebrief’s corporate security stack across endpoints, identity, SaaS, browsers, Zero Trust, EDR, SIEM, and MDM. Establish secure configuration baselines, detect and remediate drift, integrate telemetry, and build API-driven or infrastructure-as-code automation. Translate CMMC 2.0 and NIST-aligned requirements into continuously validated technical controls and reliable audit evidence. Partner with Corporate IT, Security Operations, GRC, and application owners to strengthen security posture and reduce manual compliance work.
Top Skills: Configuration ManagementCrowdstrikeEdrGithub ActionsInfrastructure-As-CodeMdmMfaOktaOkta WorkflowsRest ApisSIEMSplunkSsoWebhooksWorkspace OneZero TrustZscaler
11 Days Ago
Remote
United States
134K-180K Annually
Entry level
134K-180K Annually
Entry level
Software • Defense
Own the credibility of AtomEngine’s military simulation entity catalog. Lead catalog strategy, research standards, quantitative performance modeling, AI-directed content production, verification and validation, automated testing, competitive wargames, documentation, and analyst mentoring. Partner with customers, engineers, and subject matter experts to prioritize catalog development, defend modeling assumptions, identify inaccuracies, and continuously improve simulation data quality.
Top Skills: Agentic Ai WorkflowsAtomengineAutomated TestingBug-Tracking SystemsGame Modding ToolsSimulation Authoring EnvironmentsVersion Control Systems
11 Days Ago
Remote
United States
185K-230K Annually
Senior level
185K-230K Annually
Senior level
Software • Defense
Build and scale Onebrief’s agentic design system platform, including components, utilities, documentation, governance, automated intake, evaluation, release QA, and production telemetry. Lead moonshot projects focused on agentic customer experiences, establish appropriate human-review gates, integrate systems with Docker, Kubernetes, AWS EKS, and GitHub CI/CD, and advise design leadership on strategy and roadmap. The role requires cross-functional leadership, technical judgment, and playbook creation in an ambiguous environment.
Top Skills: Amazon EksAWSDockerGithub Ci/CdKnowledge GraphsKubernetesModel Context Protocol (Mcp)Vector Stores
About Onebrief

Onebrief is collaboration and AI-powered workflow software designed specifically for military staffs. By transforming this work, Onebrief makes the staff as a whole superhuman - meaning faster, smarter, and more efficient.

We take ownership, seek excellence, and play to win with the seriousness and camaraderie of an Olympic team. Onebrief operates as an all-remote company, though many of our employees work alongside our customers at military commands around the world.

Founded in 2019 by a group of experienced planners, today, Onebrief’s team spans veterans from all forces and global organizations, and technologists from leading-edge software companies. We’ve raised $320m+ from top-tier investors, including Battery Ventures, General Catalyst, Sapphire Ventures, Insight Partners, and Human Capital, and today, Onebrief is valued at $2.15B. With this continued growth, Onebrief is able to make an impact where it matters most.

Security Clearance, Location, and Onsite Notice:

This role is remote. The role may require occasional (once per quarter or less) on-site activities at customer locations.

Must be a US Citizen, eligible for a Secret Security Clearance. Active Secret or Top Secret Clearance is a plus, SCI eligibility is a plus.

About The Role

We are hiring an Application Security Engineer to join our Infrastructure & Security team. You’ll report to our Director of Infrastructure and work closely with fellow SREs, Software Engineers, DevOps Engineers, Platform Engineers, Customer Relations, and Cybersecurity Analysts.

You will be helping identify, triage and fix security issues within the Onebrief application and related platform and deployed infrastructure.

About You

You are a security-minded individual who knows that vulnerabilities in modern software are an existential business risk. Maybe you love reading incident reports, and perhaps you even participate in security conferences like DefCon or OWASP meetups. Ideally, you have experience in a related field like software engineering, DevOps or systems administration. You are familiar with modern cloud-native technologies like Kubernetes and have experience with software development. Maybe you have experience with game cheat development/detection, bug bounties, or maybe you come from a traditional enterprise security background.

What You’ll Do

You will own the security and compliance posture of our software products and platform. You will do this by:

  • Find Vulnerabilities in our Software: Bring an attacker’s mindset to review PRs, perform code audits, and utilize static analysis to identify vulnerable code patterns that can be exploited by adversaries. Use dynamic analysis, fuzzers and code reviews to find weaknesses in our codebase and work with developers to patch them.

  • Fix Vulnerabilities Across the Full Stack: Think like an adversary to find, fix, prevent or patch vulnerabilities from browser to kernel. Utilize vulnerability scanners to find unpatched components, and identify configuration errors that could expose our deployments to an attacker. Work with platform engineers to harden our customer environments and utilize best practices. Advise on network configuration, identity and access management and infrastructure security.

  • Improve the Security Posture of Infrastructure: Review identity and access management, logging, auditing, monitoring to help craft a layered defense for our corporate infrastructure and customer environments. Work with Cybersecurity analysts to help ensure compliance with corporate/Federal standards like SOC II, NIST and FedRamp Moderate/High.

  • Make the Team Stronger: Mentor other engineers on best security practices, share news of vulnerable libraries and compromises, engage with community on active threats and trends in exploit development, malware, etc. Work to improve processes to shift security “left” and identify vulnerabilities earlier in the design, development and deployment of our software.

What we look for:

Experience & collaboration

  • 5+ years of experience in Application Security, Cybersecurity Engineering, Software Engineering or a related field, preferably with first-hand experience ensuring security in high-compliance environments like PCI DSS, HIPAA or NIST.

  • U.S. citizenship required, security clearance greatly desired.

  • A strong understanding of Linux, containerization and orchestration, and virtual machines

  • Networking fundamentals: core protocols and secure configurations.

  • A deep understanding of incident response processes, with experience conducting thorough root cause analyses and driving continuous improvement

  • Clear, concise writing; strong documentation habits and async communication.

  • Core skills and technologies: Javascript/Browser security, Network Security, Firewalls, Intrusion Detection, Static Analysis, Dynamic Analysis, Container Scanning, Kubernetes, Docker, Helm, Ansible, Terraform, Linux, AWS, DoD compliance, Monitoring and Observability tools.

Bonus points (nice to have)

  • Experience with compliance frameworks/processes (RMF, STIGs/SRGs, PCI DSS, HIPAA, ICD 503).

  • Security considerations/design for air-gapped environments.

  • Active Security+ or another DoD 8570.01-approved security credential, or the ability to obtain the valid credentials within 3 months of employment.

  • Must-Have Skills and Qualifications:

    • Required years of experience and relevant industries.

      • 5+ years experience in Cybersecurity, Software Engineering and/or DevOps

    • Essential technical or soft skills.

      • Familiarity with DevOps practices, CI/CD

      • Familiarity with security tooling such as Static & Dynamic Analysis (SAST/DAST)

      • Familiarity with networking, web protocols

      • Working grasp of PKI, TLS and cryptographic primitives

  • Preferred Skills and Qualifications:

    • Additional skills or experience that would be advantageous.

      • JavaScript Experience

      • Security+ Certification or other IAT Level II equivalent

      • CSSLP or CISSP

      • Familiarity with DoD Software Lifecycle, RMF/ATO, STIG

      • Pentesting / Red Team experience

      • Familiarity with web authentication/authorization technologies such as SSO, SAML, OIDC, JWT, etc.

      • Experience with Kubernetes and modern Cloud-Native deployment strategies


Notice to Third Party Recruitment Agencies

Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account