Senior Application Security Engineer

Webflow
$139,000 - $250,000Remote

About The Position

At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful content management systems, AI-driven personalization, seamless hosting, and end-to-end analytics in a single, unified platform. With AI at the core, Webflow helps teams move faster, create more performant digital experiences, and scale without heavy engineering support. From independent designers and creative agencies to global enterprises, hundreds of thousands of organizations use Webflow to turn ideas into reality — and to power what’s possible on the web. We’re looking for a Senior Application Security Engineer to help us level up Webflow’s secure development practices ranging from secure coding, tooling, and improving procedures.

Requirements

  • BA/BS degree or equivalent experience
  • You bring 5+ years of application security experience, including hands-on software development, and have worked on securing high-complexity, large-scale applications.
  • You have experience in secure software design, secure coding, and modern web application security, with ability to identify security design flaws and business-logic vulnerabilities, and to drive risk-based remediation with engineering teams.
  • You have led threat modeling efforts, and/or conducted penetration testing, or manage third-party pentests, ensuring findings are clearly documented, communicated, and remediated to completion.
  • You have managed one or more of application security programs or tooling initiatives such as SCA Supply Chain, SAST, DAST and /or led bug bounty programs
  • You have contributed to security controls within large-scale solutions, including designing and/or delivering security features directly into applications (e.g., authorization models, security controls, or admin-level protections) in close collaboration with engineering and partner orgs.
  • You have experience using and building automation that leverage agentic AI, including applying AI coding agents to scale security reviews, detection, and automation responsibly.
  • You have participated in response efforts for application security incidents, from triage and containment through remediation and post-incident improvements
  • Stay curious and open to growth — actively building fluency in emerging technologies like AI to unlock creativity, accelerate progress, and amplify impact.

Responsibilities

  • Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem.
  • Bring security best practices to the software development lifecycle.
  • Work as part of a team to champion security standards while balancing business strategies and requirements.
  • Support Webflow’s security current and future compliance frameworks
  • Work to find security vulnerabilities through grey-box techniques, and propose solutions at the architecture and code level to mitigate findings.
  • Contribute code and architecture improvements to enable security within Webflow’s application for engineers.
  • Cross-train entry level application security engineers
  • In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we'll help you incorporate them into your role.

Benefits

  • Equity ownership (RSUs) in a growing, privately-owned company
  • 100% employer-paid healthcare, vision, and dental insurance coverage for full-time employees (working 30+ hours per week) and their dependents. Full-time employees may also be eligible for voluntary insurance options where applicable in the respective country of employment
  • 12 weeks of paid parental leave for both birthing and non-birthing caregivers, as well as an additional 6-8 weeks of pregnancy disability leave for birthing parents to be used before child bonding leave (note: where local requirements are more generous, employees receive the greater benefit); full-time employees also have access to family planning care and reimbursement
  • Flexible PTO for all locations and sabbatical program
  • Access to mental wellness and professional coaching, therapy, and Employee Assistance Program
  • Monthly stipends to support work and wellness
  • 401k plan or pension schemes (in countries where statutorily required), and other financial wellness benefits, like CPA and financial advisor coverage
  • Temporary employees may be eligible for paid holiday and time off, statutory leaves of absence, and company-sponsored medical benefits depending on their Fixed Term Contract and their country/state of employment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service