Application Security Engineer
Role summary
An Application Security Engineer is needed to build security into a SaaS platform, ensuring secure feature delivery. The role involves partnering with development, DevOps, and platform teams to integrate threat modeling, SAST/SCA/DAST, and rapid vulnerability response into the SDLC. Key responsibilities include protecting customer data, meeting compliance, and scaling security posture. The ideal candidate has 5+ years of experience in application security, hands-on experience securing web applications, automating AppSec workflows, and familiarity with DevSecOps and container security. Experience with GitHub Actions, Python, and TypeScript/JavaScript is required. Preferred experience includes securing LLM workflows and NIST RMF.
Vannevar is a defense technology company building AI to deter our adversaries. In the 21st century, conflict moves at algorithmic speed and foresight equals firepower. Our agentic AI is purpose-built to compete with China—from cross-Strait conflict to gray zone coercion. Trained on the most mission-relevant datasets in defense, our technology models adversary behavior, simulates campaigns, and recommends the best course of action to decision makers. Our AI systems are some of the most trusted in the industry and actively used on the front lines of the Indo-Pacific to keep the peace and save lives.
Exceptional technology starts with exceptional people. Vannevar is a small agile team combining world-class engineers with veteran strategists who bring deep expertise in defense and tradecraft. We’re building a company defined by mission impact, user empathy, and disciplined growth. In just three years, we grew from $3M to $80M in ARR, achieved early profitability, and reached unicorn status—proving that disruption doesn’t require an ego, and staying power doesn’t mean standing still.
About the role
As an Application Security Engineer, you will help build security into our SaaS platform, ensuring we can quickly ship secure features to our customers. You will partner with software, DevOps, and platform teams, while coordinating with audit partners, to embed threat modeling, automated SAST/SCA/DAST, and rapid vulnerability response into every stage of our SDLC. Your work will be pivotal in protecting customer data, meeting compliance milestones, and scaling our security posture as the company grows.
What you'll do
What you should have
Nice to have
Benefits:
