Senior Application Security Engineer
Confirmed live in the last 24 hours
Zip
Compensation
$160,000 - $220,000/year
Job Description
About Zip
Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before.
The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA.
Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups.
The Security team at Zip is responsible for protecting the confidentiality and integrity of our customers’ data. As our first Application Security Engineer, you will take on a dynamic and high impact role. You will lead our efforts to build foundational security guardrails, launch key security initiatives, and solidify trust customers place in us. Your contributions will be pivotal to the success of Zip’s rapid growth as we launch new products, such as AI Agents and an App Marketplace, and enter into new markets, including EMEA and the Federal government space. We move quickly to solve a wide range of complex technical and product challenges. While we are an experienced team that can provide constant guidance and mentorship, we value engineers who can autonomously scope and solve complex technical challenges.
You will
Design and implement technical controls to eliminate or mitigate classes of security vulnerabilities.
Support the development of secure products through design reviews, threat models, static/dynamic scans, and hands-on security assessments.
Validate, triage, and coordinate security findings from bug bounty and third party pentests.
Mentor security analysts and security champions on security best practices and techniques.
Qualifications
Experience writing production-quality code for security tooling and services
Strong written and verbal communication with internal and external stakeholders
A solid understanding of security risks and the ability to balance security with business requirements
Experience with web applications, APIs, and cloud environments. At Zip, our stack includes Python, React, GraphQL, Kubernetes, and AWS
Nice to haves
Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP
Hands-on experience in offensive security (eg, through bug bounty programs or CTFs)
The salary range for this role is $160,000 - $220,000. The salary for this position is determined based on a variety of job-related factors that may include location, relevant experience, education, or particular skills and expertise.
Perks & Benefits
At Zip, we’re committed to providing our employees with everything they need to do their best work.
Start-up equity
100% health, vision & dental coverage options
️ Catered breakfast, lunch, & dinner
Flexible PTO
️♀️ ClassPass membership
Monthly commuter benefit
Team building events & happy hours
Home office stipend
Phone/internet reimbursement
Paid parental leave
Fertility stipend
401k plan<
Similar Jobs
Netskope
IT Business Application Engineer, Workday & HR Systems
Workday
Sr Information Systems Software Application Engineer
NXP Semiconductors
Customer Application Support Engineer
Dexcom
Sr. Cybersecurity Engineer (Application and AI Security)
GE Aerospace
Staff Application Operations Engineer
Magna International