9 days ago

Senior Application Security Engineer

Quanata

Hybrid
Full Time
$285,000
Hybrid

Job Overview

Job TitleSenior Application Security Engineer
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$285,000
LocationHybrid

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Quanata

Quanata is on a mission to help ensure a better world through context-based insurance solutions. We are an exceptional, customer-centered team with a passion for creating innovative technologies, digital products, and brands. We blend some of the best Silicon Valley talent and cutting-edge thinking with the long-term backing of leading insurer, State Farm. Learn more about us and our work at quanata.com.

Our Team

From data scientists and actuaries to engineers, designers, and marketers, we’re a world-class team of tech-minded professionals from some of the best companies in Silicon Valley and around the world. We’ve come together to create the context-based insurance solutions and experiences of the future. We know that the key to our success isn't just about nailing the technology—it’s hiring the talented people who will help us continue to make a quantifiable impact.

The Senior Application Security Engineer Role

As a Senior Application Security Engineer, you will serve as the primary partner for web and backend engineering teams, helping embed security best practices throughout the software development lifecycle. You will support secure design, conduct threat modeling, review backend and frontend code, and lead integration of security tools into developer workflows. Your role bridges frontend and API security, and you'll be responsible for helping developers resolve complex security challenges across product surfaces.

Key Responsibilities

  • Partner with one product portfolio to facilitate overall product security management, emphasis on AI/ML-specific security concerns and cross-functional work with data science teams.
  • Perform security design reviews and threat modeling on APIs, web features, and service integrations, including integrating SAST, SCA, and DAST tools into CI/CD pipelines.
  • Support secure development practices across security champions and engineering.
  • Review source code and deployment configurations for security vulnerabilities.
  • Collaborate with developers to triage, fix, and validate vulnerability findings.
  • Participate in cross-functional incident response and remediation planning.
  • Draft and maintain AppSec guidance for engineering teams and security champions.
  • Contribute to security awareness and enablement across the engineering org.
  • Develop AppSec related integrations and deployments of automation solutions (ASVS scanning, Burp Suite Enterprise).
  • Support application security integration reviews, SaaS security assessments, OSS reviews.

Required Qualifications

  • Bachelor’s degree or equivalent relevant experience.
  • 6 - 8 years of experience in application security or full-stack development with security expertise.
  • Strong understanding of secure coding in JavaScript/TypeScript, Node.js, and web standards.
  • Familiar with application risk and vulnerabilities (OWASP Top 10, API Security, SSRF, etc.).
  • Experience with code scanning tools (e.g., CodeQL, Semgrep, SonarQube, Snyk).
  • Comfortable reading and debugging complex codebases across the stack.
  • Clear and thoughtful communicator with the ability to guide engineers at all levels.

Preferred Qualifications

  • Experience with GraphQL security.
  • Participation in security champions programs or secure SDLC rollouts.
  • Contributions to open-source security tooling.
  • Familiarity with infrastructure-as-code and container security.

Compensation & Benefits

Salary: $220,000 to $350,000. Please note that the final salary offered will be determined based on the selected candidate's skills and experience, as well as the internal salary structure at Quanata. Our aim is to offer a competitive and equitable compensation package that reflects the candidate's expertise and contributions to our organization.

We provide a wide variety of health, wellness, and other benefits. These include medical, dental, vision, life insurance, and supplemental income plans for you and your dependents, a Headspace app subscription, monthly wellness allowance, and a 401(k) Plan with a company match.

Additional Details

  • Work from Home Equipment: Given our virtual environment, a one-time payment of $2K will be provided to cover the purchase of in-home office equipment and furniture. Teams work with MacBook Pros, which will be delivered fully provisioned prior to your first day.
  • Paid Time Off: All employees accrue four weeks of PTO in their first year of employment. New parents receive twelve weeks of fully paid parental leave, applicable to both birthing and non-birthing parents, which may be taken within one year after birth and/or adoption.
  • Personal and Professional Development: Quanata is committed to investing in and helping its people grow. All employees receive up to $5000 each year for professional learning, continuing education, and career development. All team members also receive LinkedIn Learning subscriptions and access to multiple different coaching opportunities through BetterUp.
  • Location: We are a remote-first company for most positions, allowing you to work from anywhere in the U.S., excluding U.S. territories. Occasional travel may be requested or encouraged but is not required for most positions. Employees based in the San Francisco Bay Area or in Providence, Rhode Island may commute to one of our local offices as desired.
  • Hours: We maintain core meeting hours from 9 AM - 2 PM Pacific time for collaborating with team members across all time zones.

Quanata, LLC is an equal opportunity workplace. We are committed to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. This role is employed by Quanata, LLC, a separate company in the State Farm family of companies. If you require a reasonable accommodation, please reach out to your Talent Acquisition Partner for assistance.

Key skills/competency

  • Application Security
  • Secure SDLC
  • Threat Modeling
  • Code Review
  • Vulnerability Management
  • Incident Response
  • API Security
  • SAST/SCA/DAST
  • JavaScript/Node.js Security
  • AI/ML Security

Tags:

Application Security Engineer
Application security
secure SDLC
threat modeling
code review
vulnerability management
incident response
security architecture
secure design
developer enablement
security tools integration
JavaScript
TypeScript
Node.js
OWASP Top 10
SAST
SCA
DAST
CodeQL
Semgrep
GraphQL

Share Job:

How to Get Hired at Quanata

  • Research Quanata's mission: Study their focus on context-based insurance, innovative technology, and connection to State Farm.
  • Highlight AppSec expertise: Showcase experience in secure coding, threat modeling, and integrating SAST/SCA/DAST tools effectively.
  • Emphasize collaboration skills: Provide examples of partnering with engineering teams to embed security best practices and resolve vulnerabilities.
  • Showcase relevant technical skills: Detail proficiency in JavaScript, Node.js, web standards, OWASP Top 10, and modern code scanning tools.
  • Prepare for security deep-dives: Be ready to discuss complex security challenges, vulnerability remediation, and secure design principles.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background