Cogent Security Logo

Cogent Security

Security Engineer - Application Security (Senior)

Posted One Month Ago
Remote
Hiring Remotely in US
100K-300K Annually
Senior level
Remote
Hiring Remotely in US
100K-300K Annually
Senior level
Own product security across the SDLC: threat modeling, secure design reviews, application security testing (code review, SAST/DAST), supply-chain/dependency hardening, CI/CD security, and building automated security tooling and guardrails while partnering with engineering and product.
The summary above was generated by AI
About Cogent

Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity. AI has fundamentally changed how attacks happen, allowing malicious actors to operate at unprecedented speed and scale. Cogent’s "AI Taskforce" assesses petabytes of enterprise data to remediate these issues before critical breaches occur.

 

To stay at the cutting edge, we blend frontier research with real-world execution. Alongside our core product work, Cogent Research serves as our applied AI lab, providing the research horsepower needed to make truly agentic security workflows a reality.

 

Since coming out of stealth, Cogent has experienced rapid growth. We partner with Fortune 500 companies to secure some of the most complex production environments in the world.

 

We’re backed by Greylock and we’ve built a team with the best minds in applied AI. Our team is comprised of people from:

  • Top universities like Stanford, Berkeley, Penn, Duke, Carnegie Mellon, Waterloo

  • Preeminent research labs like Deepmind and SAIL

  • Unicorn, high-growth companies like Scale AI, Databricks, Stripe, Tesla, Coinbase

  • World class cybersecurity experts from Wiz, Abnormal AI, Zscaler

About The Role

We're hiring a Senior Application Security Engineer to own the security of the software we build. You'll partner closely with engineering to embed security into the Software Development Lifecycle (SDLC), keep our dependencies and supply chain safe, and make sure the product our customers trust is built on a secure foundation. You’ll also have the chance to influence our product, as an internal SME and early security user, your feedback loop directly shapes what we ship.

What You’ll Do
  • Embed security into the software development lifecycle: threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt

  • Own application security testing - code review, SAST/DAST, and triage - and drive issues to remediation rather than just filing them

  • Harden our software supply chain: dependency verification, safe dependency management, and CI/CD pipeline security

  • Build and automate security tooling and guardrails so security scales with engineering, not against it

  • Serve as the internal security SME on product and workflow decisions, and as an early user of what we build

  • Partner across all teams on architecture and design so security is a default, not an afterthought

What We're Looking For
  • 5+ years of extensive security engineering experience within product / application security, upholding the highest Trust standards

  • Strong hands-on engineer who ships - you produce and automate, you don't just manage process

  • Strong software engineering skills; comfortable working in code across the stack (e.g. Python, Go, Typescript, and/or similar)

  • Depth in application/product security: secure SDLC, threat modeling, code scanning, and supply-chain / dependency security

  • Fluency with the modern AI landscape and how it’s influencing the security picture - staying up to date with the rapidly changing environment

  • Able to flex up and down: strategic when it matters, in the weeds when it counts

  • Comfortable being an early security hire at a startup - high ownership, ambiguity, and direct impact

Bonus Points
  • Experience securing AI/ML products or agentic systems

  • Background contributing to developer-enablement or security-champions programs

  • Prior experience as an early security hire or building an AppSec function from scratch

For California Based Applicants

The standard base salary range for this position is $100,000 - $300,000 annually. Compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits.

We are committed to building an inclusive and diverse company. We do not discriminate based on gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.

Similar Jobs

18 Days Ago
Remote
United States
145K-183K Annually
Senior level
145K-183K Annually
Senior level
Fintech • Financial Services
Conduct manual penetration tests and secure code reviews across web applications, APIs, AWS infrastructure, and AI systems. Develop AI-assisted security tooling, test LLM applications and agents, triage SAST findings, tune detection rules, support security reviews before production, and communicate risks and remediation priorities to engineering teams.
Top Skills: Ai AgentsAPIsAWSGoLlmsPythonRubySastSecure SdlcTypescript
28 Days Ago
Remote or Hybrid
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
2 Days Ago
Remote
USA
140K-145K Annually
Senior level
140K-145K Annually
Senior level
Information Technology • Software • Cybersecurity • Defense
Leads application security engineering for enterprise systems, including SAST and DAST scanning, security control implementation, web application protection, and pipeline development. Uses Veracode, Burp tools, Linux, and programming or scripting languages to identify and remediate vulnerabilities. Applies OWASP, CVSS, CWE, federal compliance standards, and secure architecture practices while supporting scalable digital transformation initiatives. Requires Public Trust eligibility and U.S. citizenship.
Top Skills: .NetBashBurp EnterpriseBurp ProfessionalBurp ProxyC#CvssCweDastEclipseFedrampFipsHackeroneIastJavaJdeveloperLinuxNist 800-53Owasp Top 10Owasp ZapPythonSans-25SastSeleniumVeracodeVisual StudioWasc

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account