Latent Logo

Latent

Security Engineer: App Sec Lead

Reposted 15 Hours Ago
Remote
Hiring Remotely in USA
Mid level
Remote
Hiring Remotely in USA
Mid level
As an App Sec Lead, you'll build and mature an application security program, conduct code reviews, select security tools, and partner with engineering teams to ensure software security.
The summary above was generated by AI
Security Engineer: App Sec Lead

Location: Remote (US Only) or in-office option in San Francisco or New York

The Mission: Join us in building the core infrastructure that enables the mass delivery of clinical AI across American healthcare. Your work will directly translate into improving patient outcomes by accelerating access to treatment and massively increasing operational efficiency for healthcare workers.

What We Look for in a Great Application Security Engineer

We are looking for an application security engineer who is excited about building a program from scratch hand in hand with our amazing engineering team. If the following things excite you, you should apply!

  • You see a greenfield in application security and can imagine what the end product would like and how to get us there.

  • Getting your hands dirty in the code base (NodeJS/Typescript/Python), including even fixing some findings or contributing to some secure libraries, and eventually being an architect for our secure development libraries sounds like an amazing time.

  • No process for things is simply an opportunity to partner with the right engineers and leaders to build security process

  • Firing up your favorite pentesting tools and poking at the codebase yourself to see if you can find a vulnerability or two (hopefully no more than that)

  • In the near future, turning around and helping hire the rest of the application security team at Latent as the company grows

What You'll Work On (Responsibilities)

As the first dedicated application security engineer, you will be

  • Choosing the right App Sec tools for our environment to make code secure before it is shipped and working with engineering to role them out widely

  • Create and mature processes around core pillars of Latent’s security program: vulnerability management, architecture reviews, pentesting, and threat modeling

  • Doing code reviews and even a little bug fixing yourself (we are a startup after all)

  • Helping build and POC new secure ways of writing code (validation libraries, improvements to authentication/authorization practices, encryption SDKs for developers)

  • Helping re-imagine permissioning and authorization for users of the Latent platform

  • Working alongside engineers to balance business requirements with the right security controls

  • Creating a mature pentesting and/or bug bounty program to validate production code is secure

  • Bringing security checks and tooling to the places that developers work (AI-based IDEs, CI/CD, ect..)

Technical Qualifications & Environment

You should have experience creating, building, or scaling (or all three) a hands-on application security program in an organization that is cloud first.

  • Primary Coding Language: Javascript (NodeJS/Typescript) and Python

  • Experience doing threat modeling and architecture reviews

  • Experience working with engineering and technical leadership to build security processes like vulnerability management

  • Deep understanding of web and api-based security vulnerabilities (how to spot them, how to fix them, and what patterns need to be created to counter them)

  • Experience architecting (and maybe even building) access management and authorization systems

  • Bonus Points: You dabble in other areas of security (Cloud, IT, GRC ect..), have a little bit of knowhow in security detection and response, or have worked in a HIPAA-compliant environment.

Top Skills

Node.js
Python
Typescript

Similar Jobs

An Hour Ago
Remote or Hybrid
Virginia Hill, TX, USA
117K-161K Annually
Senior level
117K-161K Annually
Senior level
Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
This role involves leading and enhancing cyber threat intelligence strategies, driving automation and operations, and collaborating with various security teams to improve detection and response capabilities.
Top Skills: Cyber Threat Intelligence PlatformsEdrSIEMSoar
An Hour Ago
Remote or Hybrid
8 Locations
108K-203K Annually
Mid level
108K-203K Annually
Mid level
eCommerce • Fintech • Hardware • Payments • Software • Financial Services
The Account Services Manager will enhance and retain relationships with Sports and Entertainment sellers, identify growth opportunities, and collaborate with various teams to optimize client experiences.
Top Skills: Ai ToolsGoogle SuiteLookerRevenue.IoSalesforceSnowflake
An Hour Ago
In-Office or Remote
2 Locations
98K-162K Annually
Mid level
98K-162K Annually
Mid level
Aerospace • Information Technology • Cybersecurity • Defense • Manufacturing
The RM&SH Engineer will perform risk analysis, review supplier submittals, and mentor early career engineers, supporting aerospace technology design and sustainment.
Top Skills: Excel

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account