AdTechTalent
Engineering1 month agoHybrid

Tatari

Senior Application Security Engineer

application securityAppSecPythonJavaRustAWSKubernetesSASTDASTSCACI/CDthreat modelingsecurity automationcontainer securityLLMAIsecurity toolingAPI securitysoftware supply chain risk

Key details

Salary

$165K – $190K

Employment type

Full-time

Seniority

Mid-level

Years experience

5-10

Location

San Francisco, United States

Full job description

Tatari is seeking a mid-level full-time Application Security Engineer to define and implement security architecture for its SaaS platform. The role involves identifying vulnerabilities, designing mitigations, building security tooling and automation integrated into CI/CD pipelines, managing container security, and conducting security reviews and threat modeling. Candidates must have production Python experience, hands-on application security expertise with knowledge of OWASP and related standards, threat modeling experience, familiarity with AWS and Kubernetes security, and understanding of LLM-related risks. Responsibilities include owning SAST/DAST/SCA tooling, partnering with engineering teams on secure coding standards, and contributing to incident response. The position is hybrid with 2 days per week in-office in San Francisco, CA. Compensation ranges from $165,000 to $190,000 plus equity and benefits.

What you'll do

  • Design and execute greenfield AppSec initiatives from threat modeling to remediation
  • Build and maintain security automation integrated into CI/CD pipelines
  • Manage software supply chain risk
  • Own container security across build and runtime
  • Develop internal tooling and libraries to facilitate secure coding
  • Own SAST/DAST/SCA tooling: selection, tuning, CI/CD integration, and triage
  • Conduct application security reviews and threat models for new features and architecture
  • Identify and remediate vulnerabilities across APIs, services, and data pipelines
  • Partner with Engineering teams to establish secure coding standards and provide hands-on guidance
  • Assess and mitigate LLM-introduced risks in product features
  • Integrate agentic tooling into AppSec workflows to reduce toil
  • Contribute to security incident response for application-layer issues

Requirements

  • Production Python experience with engineering depth to review code and build security tooling
  • Hands-on application security experience, ideally at a SaaS company
  • Knowledge of OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS standards
  • Threat modeling experience with Product and Engineering teams
  • Experience building security tooling or automation (scripts, pipelines, libraries)
  • Familiarity with AWS and Kubernetes security controls related to application-layer risks
  • Working knowledge of LLM attack surfaces and mitigation
  • Experience reviewing API designs for auth anti-patterns, token mismanagement, injection risks, sensitive data exposure
  • Experience embedding with Engineering teams for code review, design consultation, standards definition
  • Experience building or maturing an AppSec program from scratch

Tech stack

PythonJavaRustAWSKubernetesSASTDASTSCACI/CDLLMAI tools

Benefits

Total compensation $165,000-$190,000Equity compensationHealth insurance coverage for employee and dependents401K, FSA, and commuter benefits$150 monthly spending account$1,000 annual continued education benefit$500 Newbie Productivity PerkUnlimited PTO and sick daysMonthly Company Wellness Day OffSnacks, drinks, and catered lunches at the officeTeam building eventsHybrid RTO of 2 days per week in office

Apply now

Ready to take the next step in your career? Click the button below to continue to the application process.

Similar jobs

More roles worth a look

Related opportunities based on specialty and working model so candidates can keep momentum.