Lead Application Security Engineer
Quick Summary
Correlate Wiz, Rapid7 or Tenable, Snyk, SAST, SCA, DAST, secrets, container, infrastructure as code, and adversarial testing observations into unique exposures. Treat corroborating tools as evidence,
Assess code findings by demonstrated outcome, including remote code execution, authentication bypass, privilege escalation, injection, server-side request forgery, arbitrary write, sensitive read,
At InvestCloud, we are building an intelligent security response capability that determines what to fix first based on the actual risk to our clients and business, not a scanner's native severity.
Traditional vulnerability management produces disconnected findings and long backlogs. It often misses whether vulnerable code is deployed, reachable by an attacker, connected to a critical service, capable of lateral movement, or already being exploited. We are solving that problem by combining threat intelligence, runtime and deployment evidence, configuration management data, attack path analysis, business criticality, and validation results.
The platform will ingest findings from infrastructure, cloud, application, software supply chain, secrets, containers, infrastructure as code, and adversarial testing. It will reconcile them to a canonical asset and service model, deduplicate them into unique exposures, and rank the remediation actions that remove the most risk.
The product is being built in Python on AWS with source-controlled connectors, deterministic policy code, an AI reasoning layer, human approval gates, complete audit evidence, and closed-loop validation. Large language models (LLMs) can correlate evidence, recommend remediation, and explain decisions. They do not calculate the authoritative priority score.
This is not another scanner or dashboard. It is a security decision and remediation platform that must answer one question reliably: what is the single next action that will remove the most material risk, why is it first, who owns it, and how will we verify the risk is gone? Every engineer on this team will build production software, operate what they build, and own the product after the initial consultant implementation.
As our Application Security & Triage Engineer, you will own the deterministic risk intelligence layer that decides what InvestCloud fixes first. You will convert observations from infrastructure and code scanners into unique exposures, enrich them with threat, deployment, reachability, attack path, client, and business context, then map them to the remediation actions that remove the most risk.
Your output is not a bucket of critical, high, and medium findings. It is one explainable action queue that identifies the single next action, the risk it removes, the affected services and clients, the accountable owner, and the evidence required for closure. The authoritative ranking must be versioned policy code, not an LLM opinion.
Responsibilities
~2 min read- →Exposure Correlation & Deduplication: Correlate Wiz, Rapid7 or Tenable, Snyk, SAST, SCA, DAST, secrets, container, infrastructure as code, and adversarial testing observations into unique exposures. Treat corroborating tools as evidence, not separate risk.
- →Deterministic Prioritization Engine: Implement and maintain the policy-as-code scoring model, tier triggers, normalized inputs, reason codes, missing data handling, and version history. Make every score reproducible, testable, explainable, and traceable to source evidence.
- →Reachability, Attack Path & Blast Radius: Evaluate production presence, network and application reachability, authentication requirements, source-to-sink paths, privileges, lateral movement, service dependencies, adjacent systems, client impact, and compensating controls.
- →Code & Software Supply Chain Risk: Assess code findings by demonstrated outcome, including remote code execution, authentication bypass, privilege escalation, injection, server-side request forgery, arbitrary write, sensitive read, and valid secrets. Use repository, commit, pipeline, SBOM, VEX, artifact, deployment, and runtime evidence rather than scanner severity alone.
- →Remediation Action Prioritization: Group the exposures resolved by each action, estimate fix coverage and confidence, calculate the total risk removed, and rank actions by tier, risk reduction, highest exposure, deadline, and verification confidence. Effort is only a final tie-breaker.
- →Calibration & Developer Guidance: Backtest rankings against real findings and expert judgment, monitor false positives and drift, refine policy safely, and translate results into concise remediation guidance that product and platform teams can act on without a security translator.
- 7+ years in application security, vulnerability management, threat exposure management, or security engineering, with evidence that you have owned risk-based prioritization at enterprise scale.
- Production Python and strong data reasoning. You can implement scoring mathematics, policy logic, unit and regression tests, data analysis, APIs, and SQL-based relationship queries yourself.
- Deep application security across SAST, SCA, DAST, API testing, secrets, containers, infrastructure as code, and software supply chain risk. You can distinguish a theoretical finding from a reachable and exploitable path.
- Threat and vulnerability intelligence depth, including CVSS, EPSS, CISA KEV, SSVC, VEX, exploit evidence, vendor advisories, fixed versions, malicious packages, source provenance, and freshness.
- Practical attack path analysis across network, identity, cloud, application, and software dependencies. You understand how an initial foothold can reach control planes, critical services, sensitive data, clients, and adjacent assets.
- Experience designing or calibrating deterministic risk models, correlation rules, confidence measures, and explainability. You preserve unknown data rather than silently treating it as zero.
- A subject matter expert who can go deep, explain the result concisely to nonexperts, show self-directed technical work, use AI responsibly to improve output, and win the cooperation of developers and service owners.
Python · SQL · pytest · Snyk · Semgrep / SonarQube · Burp Suite · OWASP ZAP · Wiz · Rapid7 / Tenable · SARIF · SBOM / VEX · CVSS / EPSS / KEV / SSVC · Jira Assets · GitLab CI · REST / GraphQL · Datadog
What We Offer
~1 min readYou will own the logic that differentiates this platform from a scanner. Without precise correlation and contextual ranking, the organization still has a larger backlog, not a better decision.
With this layer working, InvestCloud can state exactly which action should happen next and show the evidence behind it. Your judgment, code, and calibration will determine whether the team consistently removes the most material risk first.
Location & Eligibility
Listing Details
- Posted
- October 3, 2026
- First seen
- October 3, 2026
- Last seen
- October 3, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 56%
- Scored at
- October 3, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.