Application Security Consultant

USD 156,000-215,000 per year
SENIOR
✅ Remote

Tech Stack

AI @ 3 CI/CD @ 6 Communication @ 6 Django @ 4 Flask @ 4 Git @ 6 Go @ 6 JWT @ 6 Java @ 6 Machine Learning Node.js @ 4 OAuth @ 6 OWASP @ 6 Python @ 4 Security @ 7 Software Development @ 7

Details

SentinelOne is seeking an application security professional to support Wayfinder Frontier AI Services, a customer-facing offering that combines frontier AI models with offensive and defensive security expertise. The role focuses on reviewing Go, Java, and C# source code assessment results, validating findings from an agentic code-scanning pipeline, delivering customer-facing results, and helping shape scalable application security methodologies.

Responsibilities

  • Lead Wayfinder Frontier AI Services customer engagements end-to-end, including scoping, technical delivery, and presenting findings to executive and technical stakeholders.
  • Review and triage findings from the agentic code-scanning pipeline across customer Go, Java, and C# codebases.
  • Validate true positives, eliminate noise, and ensure customer findings are actionable.
  • Conduct deep code reviews across Go, Java, and C# and their common frameworks.
  • Present findings, translate technical risk into business impact, and map exposures into end-to-end exploitation chains.
  • Author and maintain SAST rule packs that scale across the customer base.
  • Partner with AI/ML engineers to improve the agentic scanning engine and reduce false positives.
  • Provide remediation guidance to customer development teams and validate fixes through follow-up reviews.
  • Mentor senior application security engineers and software-focused threat hunters.
  • Define and refine service-line methodologies, engagement playbooks, and scoping templates.

Requirements

  • 7+ years of experience in application security or product security, with a strong software development background.
  • Experience translating complex findings into technical and executive-level debriefs.
  • Excellent written and verbal communication skills.
  • Experience delivering customer-facing or consulting-style engagements end-to-end.
  • Expert-level proficiency in at least two of Go, Java, and C#, including framework-level vulnerability identification and explanation.
  • Mastery of the OWASP Top 10, CWE Top 25, and modern authentication infrastructure, including SAML, OAuth, OIDC, and JWT internals.
  • Experience driving an application through ASVS Level 4 verification.
  • Hands-on experience authoring custom static-analysis rules and queries for modern SAST engines.
  • Familiarity with AI-assisted code review workflows and validating findings from automated and agentic analysis pipelines.
  • Strong threat-modeling experience throughout the secure SDLC.
  • Fluency with Git-based source control and CI/CD pipelines, including build-pipeline security controls, runner hardening, and release-gate enforcement.
  • Experience with AI-accelerated development and code-scanning methodologies.

Nice to Have

  • Working knowledge of Python, Django, Flask, Node.js, and Express for cross-language reviews.
  • Experience reverse engineering compiled Go, Java, and C# using tools such as IDA Pro, Binary Ninja, Ghidra, dnSpy, ILSpy, JAD, or CFR.
  • OSWE, CSSLP, or GWAPT certification; published CVEs; or conference talks.
  • Familiarity with SOC 2, ISO 27001, or FedRAMP control mapping.

Benefits

  • Restricted Stock Units and Employee Stock Purchase Plan.
  • Flexible time off, paid company holidays, paid sick time, gender-neutral parental leave, and grandparent leave.
  • Medical, dental, and vision coverage.
  • 401(k) retirement plan with company match.
  • Life and disability insurance, health and dependent care FSA, and voluntary insurance benefits.
  • Employee Assistance Program, prepaid legal benefits, pet insurance, Cancer Care program, and global business travel medical insurance.
  • Home office allowance and mobile phone reimbursement.
  • Wellness coach, wellness or gym reimbursement, fertility coverage, and adoption and surrogacy reimbursement.

This is a U.S. role with a location-dependent base salary range of $156,000–$215,000 USD. SentinelOne is an Equal Employment Opportunity and Affirmative Action employer and participates in the E-Verify Program for U.S.-based roles.

More jobs at SentinelOne

Similar jobs