Lead Application Security Engineer
Quick Summary
We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on capturing civilizational levels of ultra-low-cost renewable energy for applications including computing and affordable renewable fuels delivered to shore.
The company is a public benefit corporation headquartered in Portland, Oregon, and backed by leading venture capitalists, philanthropic investors, university endowments, and private investment offices. We operate as an idea meritocracy in which the best ideas change the company’s direction on a regular basis.
Our staff have worked at organizations such as SpaceX, Blue Origin, Boeing, Tesla, Apple, Virgin Orbit, Astra, Google, Amazon, Microsoft, New Relic, Bridgewater, Raytheon, Disney Imagineering, and the US Army and Air Force, as well as research universities, startups, and small companies across a range of industries.
About the Role
~1 min readOur core technology is the node, a device that produces energy in the ocean’s harshest conditions for years at a time without human maintenance or intervention.
As a Lead Application Security Engineer, you will play a key role in advancing Panthalassa’s application security capabilities, partnering closely with the Director of Information Security and software engineering teams. You will bring broad application security and software engineering expertise, strong technical judgment, and the ability to quickly understand unfamiliar languages, frameworks, and architectures. Candidates should possess broad application security and software engineering skills, and be able to quickly come up to speed with languages and frameworks with which they have not previously worked.
Candidates should have strong interpersonal skills and be able to thrive in a creative, scrappy, and collaborative environment in which the best ideas change the company’s direction on a regular basis.
Responsibilities
~1 min read- →Assist the Head of Information Security with building out the AppSec function at Panthalassa.
- →Conduct code and service architecture reviews to provide security guidance.
- →Lead engineers in threat modelling applications and services.
- →Work with the Head of Information Security to define culturally useful software security metrics.
- →Assist in interviewing and onboarding of other Security personnel.
- →Assist with incident response and handling now while we grow, and provide escalation support for incidents later as we have grown.
- →Integrate, maintain, and automate security scanning tools (SAST, DAST, SCA, and secrets management) directly into our CI/CD pipelines.
- →Build and integrate agentic security tools for Panthalassa needs.
- →Conduct hands-on threat modeling and architectural design reviews for new features and applications before code is written.
- →Perform manual and automated secure code reviews as well as targeted penetration testing on web and mobile applications.
- →Help manage the company’s external Vulnerability Disclosure or Bug Bounty programs and translate regulatory compliance requirements into practical engineering tasks.
Requirements
~1 min read- 6+ years of experience with Application Security processes.
- 2+ years of experience as a Team Lead or Manager of an Application Security team.
- Both broad in general and deep in places Application Security foundational knowledge.
- Experience with using AI systems and agents for security outcomes in a professional capacity.
- Deep understanding of the OWASP Top 10, CWE Top 25, and secure design patterns.
- Hands-on experience with industry-standard security tools (e.g. Snyk, GitHub Advanced Security, Burp Suite, Fortify).
- Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience.
- Experience with software development work related to mechanical engineering environments.
- Familiarity with cloud platforms (AWS, Azure, or GCP) and modern infrastructure tools like Docker, Kubernetes, and Infrastructure as Code (IaC).
The above qualifications are desired, not required. We encourage you to apply if you are a strong candidate with only some of the desired skills and experience listed.
- Travel to conferences, vendors and test sites as needed.
- Intermittently able to work longer hours and weekends to support critical needs. While we expect a lot of each other, we also offer a high degree of autonomy and work-life balance, including flexible PTO and flexible working hours.
What We Offer
~1 min readIf hired for this full-time role, you will receive:
This is an on-site position. Our offices, lab, and shop are located in Portland, Oregon.
Location & Eligibility
Listing Details
- Posted
- October 7, 2026
- First seen
- October 7, 2026
- Last seen
- October 7, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 79%
- Scored at
- October 7, 2026
Signal breakdown
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
