Siftstack

Senior Application Security Engineer

Marina Del Rey, California, United StatesFull timeSenior$180,000 - $230,000 / yearPosted 13 days ago
Apply on Siftstack →

Sign in to see who you know at Siftstack.

ABOUT SIFT

Sift is the data infrastructure platform for hardware engineering teams. We turn high-frequency telemetry into engineering insights for mission-critical machines: rockets, satellites, autonomous vehicles, energy systems, and defense platforms. Founded by former SpaceX engineers, we are building the review and analysis layer for the AI era of physical systems.

In This Role, You’ll

  • Secure-by-default guardrails: Build the patterns, libraries, and standards for authentication, authorization, input handling, and cryptography that make whole classes of vulnerability hard to introduce. Ensure the secure path is the path of least resistance.
  • Software supply chain: Own dependency integrity, artifact signing, and build-pipeline trust. This matters especially for the self-managed and air-gapped deployments our customers run.
  • Threat modeling and secure design: Partner with engineering teams on new features and architectural changes across a distributed, polyglot system, and turn the results into concrete design decisions.
  • Developer-facing security tooling: Own the appsec toolchain in CI/CD: SAST, software composition analysis, secret scanning, and fuzzing. Tune it so developers get findings worth acting on, then work with the owning teams to drive remediation.
  • Raise engineering’s security fluency: Make security knowledge something engineers pick up from design reviews, documentation, and working with you, not something they have to come ask for.

The Skillset You’ll Bring

  • 5+ years building production software, including direct security ownership of a codebase you shipped. You are a software engineer first, applying that skill to security.
  • Fluency reading and reviewing a compiled systems language, with depth in Go or Rust.
  • Strong grounding in application security: web and API vulnerability classes, authentication and authorization patterns, and applied cryptography, applied through threat modeling and design review on distribute...