Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
CI/CD @ 6
Communication @ 6
Django
Flask
Git @ 6
JWT @ 7
Java @ 6
Machine Learning
Node.js
OAuth @ 7
OWASP @ 7
Python
Rust @ 6
Security @ 7
Software Development @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
SentinelOne is seeking an application security professional to support Wayfinder Frontier AI Services, a customer-facing offering that combines frontier AI models with offensive and defensive security expertise. The role focuses on reviewing C, C++, Rust, and Java source code assessments, validating findings from an agentic code-scanning pipeline, delivering results to technical and executive audiences, and helping scale the service methodology.
Responsibilities
- Support Wayfinder Frontier AI Services customer engagements end-to-end, including scoping work, delivering technical findings, and presenting results to executive and technical stakeholders.
- Review and triage findings from the agentic code-scanning pipeline against customer C, C++, Rust, and Java codebases.
- Validate true positives, eliminate noise, and ensure customer findings are actionable.
- Conduct deep code reviews across C, C++, Rust, and Java codebases and common frameworks.
- Present findings, translate technical risk into business impact, and map exposures into end-to-end exploitation chains.
- Author and maintain SAST rule packs that scale across the customer base.
- Partner with AI/ML engineers to improve the agentic scanning engine.
- Provide remediation guidance to customer development teams and validate fixes through follow-up reviews.
- Work with engineering teams to enhance the agentic code-scanning pipeline and reduce false positives.
- Collaborate with software-focused threat hunters and other team members to raise technical standards.
Requirements
- 5+ years of experience in application security or product security, with a strong software development background.
- Proven ability to translate complex findings into technical and executive-level debriefs.
- Excellent written and verbal communication skills.
- Experience delivering customer-facing or consulting-style engagements end-to-end.
- Ability to work comfortably in a distributed remote organization.
- Proficiency in at least two of C, C++, Rust, and Java, including experience identifying and explaining framework-level vulnerabilities and secure coding methodologies.
- Strong knowledge of the OWASP Top 10, CWE Top 25, and modern authentication infrastructure, including SAML, OAuth, OIDC, and JWT internals.
- Experience driving an application through ASVS Level 4 verification is a plus.
- Hands-on experience authoring custom static-analysis rules and queries for modern SAST engines.
- Familiarity with AI-assisted code review workflows and validating findings from automated and agentic analysis pipelines.
- Strong threat-modeling experience throughout the secure SDLC.
- Fluency with Git-based source control and CI/CD pipelines, including build-pipeline security controls, runner hardening, and release-gate enforcement.
- Experience with AI-accelerated development or code-scanning methodologies.
Nice to Have
- Working depth in Python, including Django or Flask, and Node.js, including Express.
- Reverse engineering experience with compiled C, C++, Rust, or Java using IDA Pro, Binary Ninja, or Ghidra.
- OSWE, CSSLP, or GWAPT certification; published CVEs; or conference talks.
- Familiarity with SOC 2, ISO 27001, or FedRAMP control mapping.
Benefits
- Restricted Stock Units (RSUs) and Employee Stock Purchase Plan (ESPP).
- Flexible time off, paid company holidays and sick time, gender-neutral parental leave, and grandparent leave.
- Medical, dental, and vision coverage.
- 401(k) retirement plan with company match.
- Life and disability insurance, health and dependent care FSA, and voluntary benefits.
- Employee Assistance Program, ARAG pre-paid legal, nationwide pet insurance, Cancer Care program, and global business travel medical insurance.
- Home office allowance and mobile phone reimbursement.
- Wellness coach, wellness/gym reimbursement, fertility coverage, and adoption and surrogacy reimbursement.
Compensation
The U.S. base salary range is $132,000–$160,000 USD annually, with location-based variations possible.
More jobs at SentinelOne
Senior Threat Hunter
SentinelOne · United States
USD 108,000-130,000 per year
Engagement Manager
SentinelOne · United States
USD 132,000-160,000 per year
Senior Staff Forward Deployed Engineer, AI
SentinelOne · United States
USD 184,000-253,000 per year
Staff Forward Deployed Engineer, AI
SentinelOne · United States
USD 156,000-215,000 per year
Staff Site Reliability Engineer
SentinelOne · United States
USD 156,000-200,000 per year
Similar jobs
Application Security Consultant
SentinelOne · United States
USD 156,000-215,000 per year
Application Security Consultant
SentinelOne · United States
USD 156,000-215,000 per year
Staff Software Engineer - Site Defense
Reddit · United States
USD 217,000-303,900 per year
Senior Staff Client Platform Engineer
Nvidia · Santa Clara, United States
USD 200,000-322,000 per year
Senior Storage Production Engineer - DGX Cloud
Nvidia · Santa Clara, United States
USD 176,000-333,500 per year
Senior Storage Production Engineer - DGX Cloud
Nvidia · Santa Clara, United States
USD 176,000-333,500 per year
Application Security Engineer
SpaceXAI · Palo Alto, United States
USD 100,000-258,000 per year
Senior AI Workflow Engineer
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year