AdTechTalent
Engineering6 days agoHybrid

Tatari

Senior Application Security Engineer

application securityAppSecPythonJavaRustAWSKubernetesSASTDASTSCACI/CDthreat modelingsecurity automationcontainer securityLLMAIsecurity toolingAPI securitysoftware supply chain risk

Key details

Salary

$165K – $190K

Employment type

Full-time

Seniority

Mid-level

Years experience

5-10

Location

San Francisco, United States

Full job description

Tatari is seeking a mid-level full-time Application Security Engineer to define and implement security architecture for its SaaS platform. The role involves identifying vulnerabilities, designing mitigations, building security tooling and automation integrated into CI/CD pipelines, managing container security, and conducting security reviews and threat modeling. Candidates must have production Python experience, hands-on application security expertise with knowledge of OWASP and related standards, threat modeling experience, familiarity with AWS and Kubernetes security, and understanding of LLM-related risks. Responsibilities include owning SAST/DAST/SCA tooling, partnering with engineering teams on secure coding standards, and contributing to incident response. The position is hybrid with 2 days per week in-office in San Francisco, CA. Compensation ranges from $165,000 to $190,000 plus equity and benefits.

What you'll do

  • Design and execute greenfield AppSec initiatives from threat modeling to remediation
  • Build and maintain security automation integrated into CI/CD pipelines
  • Manage software supply chain risk
  • Own container security across build and runtime
  • Develop internal tooling and libraries to facilitate secure coding
  • Own SAST/DAST/SCA tooling: selection, tuning, CI/CD integration, and triage
  • Conduct application security reviews and threat models for new features and architecture
  • Identify and remediate vulnerabilities across APIs, services, and data pipelines
  • Partner with Engineering teams to establish secure coding standards and provide hands-on guidance
  • Assess and mitigate LLM-introduced risks in product features
  • Integrate agentic tooling into AppSec workflows to reduce toil
  • Contribute to security incident response for application-layer issues

Requirements

  • Production Python experience with engineering depth to review code and build security tooling
  • Hands-on application security experience, ideally at a SaaS company
  • Knowledge of OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS standards
  • Threat modeling experience with Product and Engineering teams
  • Experience building security tooling or automation (scripts, pipelines, libraries)
  • Familiarity with AWS and Kubernetes security controls related to application-layer risks
  • Working knowledge of LLM attack surfaces and mitigation
  • Experience reviewing API designs for auth anti-patterns, token mismanagement, injection risks, sensitive data exposure
  • Experience embedding with Engineering teams for code review, design consultation, standards definition
  • Experience building or maturing an AppSec program from scratch

Tech stack

PythonJavaRustAWSKubernetesSASTDASTSCACI/CDLLMAI tools

Benefits

Total compensation $165,000-$190,000Equity compensationHealth insurance coverage for employee and dependents401K, FSA, and commuter benefits$150 monthly spending account$1,000 annual continued education benefit$500 Newbie Productivity PerkUnlimited PTO and sick daysMonthly Company Wellness Day OffSnacks, drinks, and catered lunches at the officeTeam building eventsHybrid RTO of 2 days per week in office

Apply now

This MVP uses a placeholder application flow. In production, this section can connect to an external apply URL or a native application form.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.