Senior Application Security Engineer
117k - 160k USD
Remote
Full Time
#Application Security
#Penetration Testing
#Security Engineering
#OWASP Top 10
#Node.Js
#Python
#Burp suite
#OWASP
#SAST
#DAST
#SCA
#Vulnerability Management
Unqork is transforming the way enterprises build, test, and run AI-native applications. By helping organizations in highly regulated sectors reduce technical debt and improve security over time, we enable businesses to prioritize innovation. Our platform is trusted by major global institutions, including Goldman Sachs, Marsh, BlackRock, and the U.S. Department of Health and Human Services. We are currently looking for a Senior Application Security Engineer to join our remote-first team and help protect our Commercial and FedRAMP technology stacks.
Key outcomes
- Conduct manual penetration testing and security assessments to identify complex vulnerabilities that automated tools might miss.
- Manage and triage results from SAST, DAST, and SCA tools to prioritize risks and reduce false positives.
- Perform deep-dive security code reviews, specifically focusing on Node.js applications to uncover logic flaws and access control issues.
- Build Python automation scripts to streamline security tasks and integrate checks directly into CI/CD pipelines.
- Partner closely with engineering teams to guide them through vulnerability remediation and foster a culture of Security by Design.
- Maintain expertise in the OWASP Top 10 and related frameworks to keep our defensive strategies ahead of emerging threats.
- Utilize AI tools to enhance workflows and explore creative ways to automate security processes.
Requirements
- At least 5 years of professional experience in application security, penetration testing, or security engineering.
- Expert-level knowledge of the OWASP Top 10, including the ability to explain root causes and remediation for common web attack vectors like SQLi, XSS, and SSRF.
- Hands-on experience testing AI and LLM applications, with a strong understanding of the OWASP LLM Top 10.
- Proficiency in auditing Node.js code and writing custom automation scripts using Python.
- Practical experience using Burp Suite Professional, OWASP ZAP, and various commercial security platforms.
- Strong communication skills, with the ability to translate technical security findings for non-technical stakeholders.
Compensation
We offer a competitive salary based on a geographic tier system to reflect local market rates. The base salary ranges are as follows:
- Tier 1 (New York, Seattle, and San Francisco Metro areas): $129,600 - $160,000.
- Tier 2 (All other U.S. locations): $116,640 - $144,000.
In addition to base pay, you may be eligible for target incentives and company equity in the form of stock options. Our benefits package includes:
- Remote work flexibility with a home office stipend.
- Unlimited paid time off.
- Comprehensive medical, dental, and vision insurance for you and your dependents.
- Employer-sponsored 401k with a contribution match.
- Paid parental leave and a student loan payback program.
- Flexible hours and a subsidized ClassPass membership.
How to apply
If you are an innovative thinker who enjoys challenging the status quo and securing complex technology, we invite you to apply. We look forward to reviewing your background and discussing how you can contribute to our mission.








