Back to jobs
New

Staff Application Security Engineer

Remote (US)

Company Background

Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.

Location:

This position is remote within the United States or Canada.

At Censys, we’re on a mission to provide best in class internet visibility and intelligence to the global security community. Our platform helps security teams uncover hidden threats, gain actionable insights, and build proactive defense strategies. Trusted by organizations worldwide, Censys cuts through the noise to surface the most critical risks, enabling teams to respond faster, and stay ahead of attackers. We’re constantly pushing the boundaries of what’s possible to help our customers see and secure the internet more clearly than ever before.

Role Summary:

Censys is seeking a Staff Application Security Engineer to join our Infrastructure and Operations Platform (SRE) team. In this role, you’ll own the application security strategy for how Censys builds and ships software — designing the secure paths, guardrails, and automation that let our engineers develop and deploy quickly, confidently, and securely. You’ll set technical direction across the software lifecycle, from infrastructure-as-code and container security to secure deployment workflows and the security of our AI/ML-enabled services. As a security company, we hold ourselves to the standard we help our customers achieve; this role is central to making that real. We expect all of our employees to consider customer happiness as our primary goal and to come to work every day eager to learn and educate, helping to make us a better organization every day.

What You’ll Do:

  • Own and drive the AppSec/DevSecOps program roadmap across engineering, defining the strategy for embedding security into the SDLC through shift-left practices, paved roads, and automation rather than gates
  • Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform (GCP), including support for AI/ML workloads
  • Lead the integration of security into CI/CD pipelines — code scanning, secret detection, software composition analysis, and infrastructure policy enforcement — partnering with engineering teams to adopt them without friction
  • Deliver capabilities such as hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and risk across the organization
  • Set the security architecture direction for AI/ML workflows, implementing controls around model training, deployment, and inference pipelines, including access control, artifact validation, input/output sanitization, and model provenance tracking
  • Partner with CorpSec on company security and compliance initiatives, owning the engineering side of the requirements by designing and implementing controls for SOC 2 and ISO27001 audit readiness, as well as improving tooling around BCDR, infrastructure policies, and service inventory accuracy
  • Provide technical leadership and mentorship, raising the security bar through design reviews, threat modeling, and pragmatic guidance to engineers across all teams
  • Participate in a shared on-call rotation with the Infrastructure and SRE teams, supporting production uptime and security incident response readiness

What You’ll Bring:

  • 10+ years of experience in Security Engineering, DevSecOps, SRE, or related roles, with a track record of leading security initiatives that span multiple teams
  • Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections (e.g., Helm, Crossplane)
  • Strong experience with Application Security tooling — dependency scanning, static analysis, and policy enforcement — integrated into CI/CD pipelines such as GitHub Actions and ArgoCD, and the ability to bridge engineering practices with Security Operations
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs), and familiarity with frameworks like MITRE ATT&CK
  • Strong grasp of cloud services (GCP preferred), especially securing data pipelines, model hosting endpoints, and related infrastructure
  • Proficiency with Infrastructure-as-Code (Terraform, Crossplane, or similar) and security scanning for cloud resources
  • Proficiency with scripting and automation (e.g., Python, Bash)
  • The ability to thoughtfully participate in technical discussions and drive towards data-driven decisions amidst ambiguity and competing priorities
  • Strong communication skills and empathy for developer needs, with a demonstrated ability to embed secure practices without creating friction

What Sets You Apart:

  • Experience building or scaling an AppSec or DevSecOps program from early maturity, including establishing paved roads and measuring adoption
  • Familiarity with commercial security platforms such as Orca Security (CNAPP/cloud security posture) and Aikido Security (application security scanning) is a plus
  • Experience securing ML toolchains (e.g., TensorFlow, PyTorch) and familiarity with AI-specific threats such as data leakage, model inversion, prompt injection, and adversarial inputs
  • Hands-on experience integrating and managing Web Application Firewalls (WAF), anti-DDoS systems, and edge protection technologies
  • Familiarity with monitoring and observability systems (e.g., Prometheus, Grafana, OpenTelemetry) with a focus on detecting security anomalies
  • Familiarity with AI governance and compliance standards (e.g., EU AI Act, NIST AI Risk Management Framework)
  • Strong interest in harnessing AI and LLM tools as a force multiplier — using them to code smarter, iterate faster, boosting productivity and enhancing product capabilities

 

For high cost of living areas (San Francisco Bay, New York City, and Seattle), the expected salary range for this position is $198,000 USD – $233,000 USD, plus bonus eligibility and equity.

For all other US locations, the expected salary range for this position is $172,000 USD – $216,000 USD, plus bonus eligibility and equity.

Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 83% and 100% of range. Please discuss your specific work location with your recruiter for more information.

Censys offers a competitive benefits package to employees, including equity, health, dental & vision coverage, retirement with company contribution, parental leave, mental health & wellness benefits, flexible PTO, and a professional development stipend. Censys also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Censys’s compensation and benefits are subject to change and may be modified in the future. Please see our careers page for more details.

We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to your recruiter. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities.

To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates to keep their cameras on during video interviews. Additionally, if hired, we would love to bring you to our HQ in Ann Arbor for in-person onboarding.

By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with our Censys Privacy Policy.


Our roots are in Ann Arbor, Michigan and our innovation is fueled by the team’s global perspectives. For this role, we are open to remote employees across the continental US. We value diversity and are committed to creating an inclusive environment for all employees. Censys is an equal opportunity employer.

#LI-DNI

Note to external recruiters/agencies: We are not currently engaging with third-party agencies for this role and will not accept unsolicited outreach. We kindly ask that you do not submit resumes or candidate profiles to our team.

California Privacy Rights Notice

Pursuant to the California Consumer Privacy Act (CCPA), we are providing you with notice that we collect personal information from job applicants for business purposes, including evaluating your candidacy for employment, conducting interviews, and, if applicable, completing the hiring process. The categories of information we may collect include identifiers (such as name and contact information), professional or employment-related information (such as work history, education, and references), and other information you provide in your application. We do not sell or share your personal information. For more information on how we use and protect your personal information, and your rights under the CCPA, please refer to our Privacy Policy.

Create a Job Alert

Interested in building your career at Censys? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Censys’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.