Haystack
← Back to Jobs
Technology
IC

Senior Application Security Engineer- 7+ yrs- San Jose, United States- Onsite

iMedhas Consulting ServicesSan Jose, CA🇺🇸United StatesPosted Sep 16, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
San Jose, CA, United States
Posted
23 hours ago
OWASPC++JavaPython

Job Description

Job Description :

Job Requirements Role OverviewSan jose CA, 5 days/week, need local profiles.Support the Search Engineering team by managing vulnerability lifecycles, ensuring secure architectural practices, and overseeing automated fix validations.Key Responsibilities :Threat Modeling & Asset Profiling: Document trust boundaries, data flows, and architectural entry points for high-priority services; maintain up-to-date threat profiles in centralized repositories.Vulnerability Triage & Policy Management: Review and filter scanner findings, classify severity, and evaluate exception requests against security policies.Reproduction & PoC Validation: Construct minimal test environments/harnesses to validate reported findings and confirm viable vulnerabilities vs. false positives.Automated / Agentic Fixer Oversight & QA: Supervise and validate code patches generated by automated remediation agents, executing tests and inspecting diffs for regressions.Product Team Coordination & Closure: Route validated patches to code owners and shepherd fixes through code review to production deployment.Technical SkillsMust-Have Skills:Understanding of architectural trust boundaries, attack surfaces, data flows, and threat modeling frameworks (e.g., STRIDE, PASTA).Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10) and SLA mapping.Proficiency reading and writing code in at least two core languages (C++, Go, Java, Python) and building test harnesses/PoCs.Strong code review skills (identifying regressions, hallucinations) and knowledge of secure coding standards.Nice-to-Have / Advanced Skills:Experience with threat model reviews for large distributed / microservice architectures.Experience managing vulnerability queues, automated scanning tools, and compliance exception reviews.Practical experience with fuzzing, unit test frameworks, sandbox execution, and cross-boundary debugging.Experience prompt-tuning automated code generation tools, differential testing, and patch validation.Work Experience 5-7Years

Similar jobs