You will build the security layer for how Workleap writes software, and then you will teach it to run itself. Today that means the traditional stack done properly. SAST, DAST, SCA, and secret scanning wired into GitHub Actions so findings land where developers already work, with the noise tuned out rather than tolerated. Threat modeling on architectural changes. Vulnerability intake and triage that closes the loop instead of filling a backlog. Where it goes next is the actual reason this role exists. We are moving toward agentic security review, where agents perform the first pass on every pull request, reason about the change in context, and escalate what matters to a human. Nobody has fully solved this. Rules engines miss intent, models hallucinate findings, and the gap between the two is where the interesting work is. You will close that gap, and you will decide how much trust the system earns at each step. You will be a hands on individual contributor. You will write the code.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed