Full job description
Tatari is seeking an Application Security Engineer to define security architecture and lead AppSec initiatives for its SaaS platform. The role involves identifying vulnerabilities, designing mitigations, building security tooling and automation integrated into CI/CD pipelines, managing container security, conducting security reviews and threat modeling, and partnering with Engineering teams to establish secure coding standards. Candidates must have production Python experience, hands-on application security expertise, knowledge of security standards (OWASP, API Security Top 10, ASVS, etc.), threat modeling experience, familiarity with AWS and Kubernetes security, and understanding of LLM-related risks. Benefits include total compensation of $165,000-$190,000, equity, health insurance, 401K, education benefits, unlimited PTO, and hybrid work with 2 days in office per week.
What you'll do
- Design and execute greenfield AppSec initiatives across SaaS platform from threat modeling to remediation
- Build and maintain security automation integrated into CI/CD pipelines and manage software supply chain risk
- Own container security across build and runtime
- Develop internal tooling and libraries to facilitate secure coding for application engineers
- Own SAST/DAST/SCA tooling: selection, tuning, CI/CD integration, and triage
- Conduct application security reviews and threat models for new features and architectural changes
- Identify and remediate vulnerabilities across APIs, services, and data pipelines
- Partner with Engineering teams to establish secure coding standards and provide hands-on guidance
- Assess and mitigate LLM-introduced risks in product features
- Integrate agentic tooling into AppSec workflows to reduce toil
- Contribute to security incident response when application-layer issues are involved
Requirements
- Production Python experience with engineering depth to review code and build security tooling
- Hands-on application security experience, ideally at a SaaS company
- Knowledge of security standards such as OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS
- Threat modeling experience with Product and Engineering teams
- Experience building security tooling or automation (scripts, pipelines, libraries)
- Familiarity with AWS and Kubernetes security controls related to application-layer risks
- Working knowledge of LLM attack surfaces and mitigation
- Experience reviewing API designs for auth anti-patterns, token mismanagement, injection risks, and sensitive data exposure
- Experience embedding with Engineering teams for code review, design consultation, and standards definition
- Experience building or maturing an AppSec program from scratch
Tech stack
PythonJavaRustAWSKubernetesSASTDASTSCACI/CDLLM
Benefits
Total compensation ($165,000-$190,000)Equity compensationHealth insurance coverage for employee and dependents401K, FSA, and commuter benefits$150 monthly spending account$1,000 annual continued education benefit$500 Newbie Productivity PerkUnlimited PTO and sick daysMonthly Company Wellness Day OffSnacks, drinks, and catered lunches at the officeTeam building eventsHybrid RTO of 2 days per week in office