Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
CI/CD @ 6
Communication @ 6
Django @ 4
Flask @ 4
Git @ 6
Go @ 6
JWT @ 6
Java @ 6
Machine Learning
Node.js @ 4
OAuth @ 6
OWASP @ 6
Python @ 4
Security @ 7
Software Development @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
SentinelOne is seeking an application security professional to support Wayfinder Frontier AI Services, a customer-facing offering that combines frontier AI models with offensive and defensive security expertise. The role focuses on reviewing Go, Java, and C# source code assessment results, validating findings from an agentic code-scanning pipeline, delivering customer-facing results, and helping shape scalable application security methodologies.
Responsibilities
- Lead Wayfinder Frontier AI Services customer engagements end-to-end, including scoping, technical delivery, and presenting findings to executive and technical stakeholders.
- Review and triage findings from the agentic code-scanning pipeline across customer Go, Java, and C# codebases.
- Validate true positives, eliminate noise, and ensure customer findings are actionable.
- Conduct deep code reviews across Go, Java, and C# and their common frameworks.
- Present findings, translate technical risk into business impact, and map exposures into end-to-end exploitation chains.
- Author and maintain SAST rule packs that scale across the customer base.
- Partner with AI/ML engineers to improve the agentic scanning engine and reduce false positives.
- Provide remediation guidance to customer development teams and validate fixes through follow-up reviews.
- Mentor senior application security engineers and software-focused threat hunters.
- Define and refine service-line methodologies, engagement playbooks, and scoping templates.
Requirements
- 7+ years of experience in application security or product security, with a strong software development background.
- Experience translating complex findings into technical and executive-level debriefs.
- Excellent written and verbal communication skills.
- Experience delivering customer-facing or consulting-style engagements end-to-end.
- Expert-level proficiency in at least two of Go, Java, and C#, including framework-level vulnerability identification and explanation.
- Mastery of the OWASP Top 10, CWE Top 25, and modern authentication infrastructure, including SAML, OAuth, OIDC, and JWT internals.
- Experience driving an application through ASVS Level 4 verification.
- Hands-on experience authoring custom static-analysis rules and queries for modern SAST engines.
- Familiarity with AI-assisted code review workflows and validating findings from automated and agentic analysis pipelines.
- Strong threat-modeling experience throughout the secure SDLC.
- Fluency with Git-based source control and CI/CD pipelines, including build-pipeline security controls, runner hardening, and release-gate enforcement.
- Experience with AI-accelerated development and code-scanning methodologies.
Nice to Have
- Working knowledge of Python, Django, Flask, Node.js, and Express for cross-language reviews.
- Experience reverse engineering compiled Go, Java, and C# using tools such as IDA Pro, Binary Ninja, Ghidra, dnSpy, ILSpy, JAD, or CFR.
- OSWE, CSSLP, or GWAPT certification; published CVEs; or conference talks.
- Familiarity with SOC 2, ISO 27001, or FedRAMP control mapping.
Benefits
- Restricted Stock Units and Employee Stock Purchase Plan.
- Flexible time off, paid company holidays, paid sick time, gender-neutral parental leave, and grandparent leave.
- Medical, dental, and vision coverage.
- 401(k) retirement plan with company match.
- Life and disability insurance, health and dependent care FSA, and voluntary insurance benefits.
- Employee Assistance Program, prepaid legal benefits, pet insurance, Cancer Care program, and global business travel medical insurance.
- Home office allowance and mobile phone reimbursement.
- Wellness coach, wellness or gym reimbursement, fertility coverage, and adoption and surrogacy reimbursement.
This is a U.S. role with a location-dependent base salary range of $156,000–$215,000 USD. SentinelOne is an Equal Employment Opportunity and Affirmative Action employer and participates in the E-Verify Program for U.S.-based roles.
More jobs at SentinelOne
Senior Manager, AI & Technology Program Management
SentinelOne · United States
USD 160,000-220,000 per year
Application Security Consultant
SentinelOne · United States
USD 156,000-215,000 per year
AI Product Manager
SentinelOne · United States
USD 184,000-253,000 per year
Staff Infrastructure Engineer
SentinelOne · United States
USD 156,000-215,000 per year
Senior Software Engineer, Agent Platform
SentinelOne · United States
USD 132,000-182,000 per year
Similar jobs
Senior Storage Production Engineer - DGX Cloud
Nvidia · Santa Clara, United States
USD 176,000-333,500 per year
Senior Storage Production Engineer - DGX Cloud
Nvidia · Santa Clara, United States
USD 176,000-333,500 per year
Senior AI Workflow Engineer
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Senior Staff Client Platform Engineer
Nvidia · Santa Clara, United States
USD 200,000-322,000 per year
Senior Systems Software Engineer - CI/CD Infrastructure for Open-Source Accelerated Computing Software
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Senior Full-Stack Lead Engineer
Nvidia · Santa Clara, United States
USD 224,000-356,500 per year
Security Software Engineer, Detection & Response Platform
Anthropic · Washington, United States, New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-405,000 per year
Security Engineer, Application Security
OpenAI · United States, New York City, United States, San Francisco, United States, Seattle, United States
USD 234,400-385,000 per year