Senior Application Security Engineer

Sift Stack, Inc.Marina del Rey, CA
$180,000 - $230,000Hybrid

About The Position

Sift is the data infrastructure platform for hardware engineering teams. We turn high-frequency telemetry into engineering insights for mission-critical machines: rockets, satellites, autonomous vehicles, energy systems, and defense platforms. Founded by former SpaceX engineers, we are building the review and analysis layer for the AI era of physical systems.

Requirements

  • 5+ years of experience building production software, with direct security ownership of a shipped codebase.
  • Software engineering background applied to security.
  • Fluency in reading and reviewing a compiled systems language, with depth in Go or Rust.
  • Strong foundation in application security, including web and API vulnerability classes, authentication and authorization patterns, and applied cryptography, applied through threat modeling and design review on distributed systems.
  • Hands-on experience embedding security tooling (SAST, SCA, secret scanning) into developer workflows and CI/CD, optimized for signal over noise.
  • A proven track record of building security tooling or libraries that have been adopted by other teams.
  • Clear communication skills, capable of explaining risk and tradeoffs to non-security professionals.
  • U.S. Citizenship Required.

Nice To Haves

  • Experience securing software deployed to customer-controlled, on-premise, or air-gapped environments.
  • Familiarity with software supply chain tooling and standards such as Sigstore, SLSA, and SBOM generation.
  • Experience with fuzzing native or high-throughput data paths.
  • Exposure to regulated environments like defense or aerospace.

Responsibilities

  • Build secure-by-default guardrails, including patterns, libraries, and standards for authentication, authorization, input handling, and cryptography, to minimize vulnerability introduction.
  • Own dependency integrity, artifact signing, and build-pipeline trust for software supply chain security, particularly for customer deployments that are self-managed and air-gapped.
  • Conduct threat modeling and secure design reviews in partnership with engineering teams for new features and architectural changes across a distributed, polyglot system, translating findings into concrete design decisions.
  • Own and manage the application security toolchain within CI/CD, including SAST, software composition analysis, secret scanning, and fuzzing. Tune these tools to provide actionable findings and collaborate with owning teams on remediation.
  • Enhance engineering's security fluency by making security knowledge accessible through design reviews, documentation, and direct collaboration.

Benefits

  • Equity
  • Benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service