Haystack
← Back to Jobs
Technology
MC

Application Security Engineer

Maven CompaniesSeattle, WA🇺🇸United StatesPosted Sep 29, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Seattle, WA, United States
Posted
17 hours ago
OWASPLLMPenetration Testing

Job Description

Role Summary

We're looking for an Application Security Engineer to lead hands-on security testing and assessment across our applications, Salesforce ecosystem, and AI-powered systems.

 

Responsibilities

  • Perform SAST, DAST, and manual penetration testing across web, API, and cloud applications.
  • Conduct security configuration reviews and validate against OWASP Top 10 principles.
  • Apply Salesforce security knowledge (profiles, permission sets, sharing rules) to assess Salesforce apps/integrations.
  • Lead threat modeling sessions for new features and architectures.
  • Conduct access/entitlement reviews across applications and platforms.
  • Perform AI/LLM penetration testing (prompt injection, data leakage, agent/tool misuse) on chatbots and AI-powered systems.
  • Document and track findings to remediation with clear risk-based reporting.

Required Skills

  • Hands-on SAST/DAST tooling experience (e.g., Semgrep, Burp Suite, ZAP).
  • Strong manual penetration testing background.
  • Solid understanding of OWASP Top 10 and Salesforce security fundamentals.
  • Experience with threat modeling and access reviews.
  • Exposure to AI/LLM security testing.
  • Strong communication skills for technical and leadership audiences.

Similar jobs