Staff Application Security Engineer
Censys
- Location
- Remote (US)
- Work model
- Remote
- Level
- Staff
- Salary
- $198k/yr
- Posted
- 11h ago
Skills
About this role
Company Background
Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.
Location
This position is remote within the United States or Canada.
At Censys, we’re on a mission to provide best in class internet visibility and intelligence to the global security community. Our platform helps security teams uncover hidden threats, gain actionable insights, and build proactive defense strategies. Trusted by organizations worldwide, Censys cuts through the noise to surface the most critical risks, enabling teams to respond faster, and stay ahead of attackers. We’re constantly pushing the boundaries of what’s possible to help our customers see and secure the internet more clearly than ever before.
Role Summary
Censys is seeking a Staff Application Security Engineer to join our Infrastructure and Operations Platform (SRE) team. In this role, you’ll own the application security strategy for how Censys builds and ships software — designing the secure paths, guardrails, and automation that let our engineers develop and deploy quickly, confidently, and securely. You’ll set technical direction across the software lifecycle, from infrastructure-as-code and container security to secure deployment workflows and the security of our AI/ML-enabled services. As a security company, we hold ourselves to the standard we help our customers achieve; this role is central to making that real. We expect all of our employees to consider customer happiness as our primary goal and to come to work every day eager to learn and educate, helping to make us a better organization every day.
What You'll Do
• Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates
• Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads
• Lead the integration of security into CI/CD pipelines — code scanning, secret detection, software composition analysis, and infrastructure policy enforcement — partnering with engineering teams to adopt them without friction
• Deliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organization
• Set the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance tracking
• Partner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracy
• Provide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teams
• Participate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readiness
What You'll Bring
• 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record