Application Security Engineer

Cerebras SystemsSunnyvale, CA

About The Position

Cerebras Systems is seeking an Application Security Engineer with a strong focus on Vulnerability Management. This role is crucial for securing Cerebras' software, infrastructure, and AI platforms. The engineer will be responsible for the vulnerability management program, encompassing discovery, risk prioritization, remediation, and verification. This is not a ticket-management position; the ideal candidate will understand vulnerabilities in context, collaborate with engineering teams, automate security tasks, and address root causes of vulnerabilities. The role involves working closely with Engineering, Infrastructure, and IT teams to identify and remediate vulnerabilities across products and environments.

Requirements

  • Strong application security or product security fundamentals and hands-on experience with vulnerability management.
  • Understand common vulnerability classes and exploitation techniques across web applications, APIs, authentication systems, cloud services, containers, and software supply chains.
  • Ability to read and reason about code and work effectively with software engineers on practical remediation.
  • Experience with vulnerability scanning and application security technologies such as SAST, SCA, DAST, secrets scanning, container scanning, or CSPM.
  • Understand vulnerability prioritization concepts including CVSS, exploitability, asset criticality, internet exposure, compensating controls, and threat intelligence.
  • Comfortable investigating security findings manually rather than relying exclusively on scanner output.
  • Ability to automate security workflows using languages such as Python, Go, or similar scripting/programming languages.
  • Experience integrating security tooling into CI/CD and modern software development workflows.
  • Comfortable working with Linux, Git, containers, and cloud environments.
  • Ability to communicate security risk clearly to both security specialists and engineering teams.
  • Approach security with an automation-first mindset and look for scalable solutions instead of manual processes.

Nice To Haves

  • Application Security or Security engineering background.
  • Securing AI/ML platforms, inference services, or large-scale compute infrastructure.
  • Building or operating vulnerability management programs at scale.
  • AWS, Kubernetes, Docker, and cloud-native environments.
  • Software supply-chain security and dependency management.
  • GitHub and CI/CD security.
  • Threat modeling and secure design reviews.
  • Penetration testing or offensive security.
  • External attack-surface management.
  • Vulnerability research or exploit validation.
  • Security data pipelines, APIs, and workflow automation.
  • Using LLMs, AI agents, or AI-assisted security tooling for vulnerability research, code analysis, penetration testing, or remediation.

Responsibilities

  • Own and continuously improve vulnerability management across applications, software dependencies, containers, operating systems, cloud infrastructure, and externally exposed services.
  • Use AI agents and advanced security models to augment vulnerability discovery, code analysis, adversarial testing, prioritization, and remediation.
  • Analyze vulnerabilities beyond scanner severity by considering exploitability, exposure, affected assets, available mitigations, and business impact.
  • Partner directly with engineering teams to triage findings, determine appropriate remediation, and drive vulnerabilities to closure within risk-based SLAs.
  • Build automation for vulnerability ingestion, deduplication, enrichment, prioritization, assignment, remediation tracking, and reporting.
  • Identify systemic vulnerability patterns and work with engineering teams to address root causes rather than repeatedly fixing individual findings.
  • Operate and improve application security capabilities including SAST, SCA, secrets detection, container scanning, infrastructure scanning, and external attack-surface monitoring.
  • Validate security findings through technical investigation and hands-on testing, distinguishing exploitable vulnerabilities from false positives and low-risk findings.
  • Perform targeted application security reviews and testing for high-risk services and features.
  • Help integrate security controls into CI/CD and developer workflows while minimizing unnecessary friction for engineering teams.
  • Develop metrics and reporting that provide meaningful visibility into vulnerability exposure, remediation performance, recurring vulnerability classes, and security risk.
  • Evaluate and integrate new security technologies as our software and infrastructure environments evolve.
  • Partner with security and engineering teams on incident response when vulnerabilities are actively exploited or require urgent remediation.

Benefits

  • Continuous learning, growth and support
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service