Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Application Security Engineer

Oneleet
CompanyOneleet
CategoryEngineering
LocationUS/EU - Remote
RemoteRemote
EmploymentNot stated
LevelNot stated
SalaryUSD 160k–220k
Posted28 May 2026
Last verified30 Jul 2026
SourceEmployer career page (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
ABOUT ONELEET Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners. Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry. WHO WE’RE LOOKING FOR: We value passionate self-starters with a growth mindset and a bias for action and personal accountability. If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you’ll fit right in. We’re especially drawn to: - Rebels with a cause — frustrated with the status quo and eager to disrupt it. - Opinionated (but not obstinate) builders — decisive yet collaborative, who help us move fast. - Clear communicators — who own their ideas and follow through. Our mission is simple: make effective cybersecurity painless. We believe cybersecurity should empower, not burden. This belief unites our team and drives every decision we make. If you’re ready to challenge the status quo and help shape the future of cybersecurity, we’d love to meet you. As an Application Security Engineer at Oneleet, you'll bring security depth to our product engineering teams as we expand our cybersecurity platform. You'll own the security judgment layer that sits between raw tooling output and what our customers actually see — deciding what to surface, what to suppress, and how to make findings genuinely useful rather than noisy. This is a hands-on, security-first engineering role at a Series A startup. You'll work closely with backend and fullstack engineers on how findings are stored, enriched, and presented, and you'll partner with product and design on what to build next. You'll be the security voice in product and engineering decisions, and you'll be empowered to push back when security judgment requires it. You'll work directly with customers — security teams using the platform day-to-day — to understand what they actually need, and iterate quickly based on their feedback. KEY RESPONSIBILITIES: - Own the integration, configuration, and output quality of security tooling that powers our platform - Tune outputs to maximize signal and minimize noise — decide what to surface, what to suppress, and what to enrich - Design rules, severity scoring, and triage flows that make findings actionable rather than overwhelming - Build the security judgment layer on top of underlying tooling — context-aware prioritization and exploitability reasoning - Partner with engineers on how findings are presented in the UI and how remediation flows work - Work with PM and design on roadmap priorities, providing the security expertise that drives what to build next - Review and shape architectural choices that affect security outcomes - Engage with customers directly to understand how they use the platform and what's blocking adoption - Benchmark our output quality against competitors and close gaps where they exist - Contribute back to the open source security tooling we depend on where it makes sense QUALIFICATIONS: - 5+ years of application security experience, with significant time shipping security products - Strong programming skills in at least one of Go, Python, or TypeScript — this is a product engineering role with security depth, not security operations - Hands-on experience tuning security tooling for production use — reducing false positives, building suppression logic, designing severity models - U
HOUSE AD995,367 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →