Staff AppSec Engineer

SentinelOne
$156,000 - $185,000Remote

About The Position

SentinelOne is seeking a Staff AppSec Engineer to lead customer-facing code security engagements. This role involves pairing frontier AI models with expert human review across C, C++, Rust, and Java codebases. The engineer will validate and triage findings from an agentic scanning pipeline, deliver technical and executive-level risk assessments, and contribute to shaping the methodology for a new service line focused on AI-driven code security. The company emphasizes continuous learning and AI fluency for all team members.

Requirements

  • 7+ years in application security or product security with a strong software development background, and a proven track record translating complex findings into technical and executive-level debriefs.
  • Experience delivering customer-facing or consulting-style engagements end-to-end, comfortable working in a distributed remote organization.
  • Expert-level proficiency in at least two of C, C++, Rust, and Java, including experience identifying and explaining vulnerabilities at the framework level, and mastery of OWASP Top 10, CWE Top 25, and modern authentication infrastructure (SAML, OAuth, OIDC, JWT internals), including experience driving an application through ASVS Level 4 verification.
  • Hands-on experience authoring custom static-analysis rules and queries for modern SAST engines, with familiarity in AI-assisted code review workflows and validating findings from automated and agentic analysis pipelines.
  • Strong threat modeling experience throughout the secure SDLC, and fluency with Git-based source control and CI/CD pipelines, including build-pipeline security controls, runner hardening, and release-gate enforcement.

Responsibilities

  • Lead Wayfinder Frontier AI Services customer engagements end-to-end — scoping the work, delivering technical findings, and presenting results to executive and technical stakeholders.
  • Review and triage findings from our agentic code scanning pipeline against customer C, C++, Rust, and Java codebases, validating true positives and eliminating noise so every finding is actionable.
  • Conduct deep manual code review across C, C++, Rust, and Java and common frameworks, translating technical risk into business impact and mapping exposures into end-to-end exploitation chains.
  • Author and maintain SAST rule packs that scale across the customer base, partnering with AI/ML engineers to improve the agentic scanning engine and reduce false positives.
  • Provide expert remediation guidance to customer development teams, validate fixes through follow-up review, and mentor senior AppSec engineers and software-focused threat hunters.
  • Define and refine the service line's core methodologies, engagement playbooks, and scoping templates.

Benefits

  • Equity & Rewards
  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Time Off & Wellbeing
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave
  • Grandparent leave
  • Insurance & Financial Security
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits (hospital, accident, critical illness)
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Work Perks & Flexibility
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness & Lifestyle
  • Wellness coach
  • Wellness/gym reimbursement
  • Fertility coverage
  • Adoption & surrogacy reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service