Application Security Engineer
Quick Summary
Vannevar is a defense technology company building AI to deter our adversaries. In the 21st century, conflict moves at algorithmic speed and foresight equals firepower.
Vannevar is a defense technology company building AI to deter our adversaries. In the 21st century, conflict moves at algorithmic speed and foresight equals firepower. Our agentic AI is purpose-built to compete with China—from cross-Strait conflict to gray zone coercion. Trained on the most mission-relevant datasets in defense, our technology models adversary behavior, simulates campaigns, and recommends the best course of action to decision makers. Our AI systems are some of the most trusted in the industry and actively used on the front lines of the Indo-Pacific to keep the peace and save lives.
Exceptional technology starts with exceptional people. Vannevar is a small agile team combining world-class engineers with veteran strategists who bring deep expertise in defense and tradecraft. We’re building a company defined by mission impact, user empathy, and disciplined growth. In just three years, we grew from $3M to $80M in ARR, achieved early profitability, and reached unicorn status—proving that disruption doesn’t require an ego, and staying power doesn’t mean standing still.
About the Role
~1 min readAs an Application Security Engineer, you will help build security into our SaaS platform, ensuring we can quickly ship secure features to our customers. You will partner with software, DevOps, and platform teams, while coordinating with audit partners, to embed threat modeling, automated SAST/SCA/DAST, and rapid vulnerability response into every stage of our SDLC. Your work will be pivotal in protecting customer data, meeting compliance milestones, and scaling our security posture as the company grows.
Responsibilities
~1 min read- →Implement and deploy enterprise standard SAST, SCA, secrets-scan, DAST, and container/IaC checks in CI/CD
- →Embed with development teams to run threat models, review critical PRs, and coach secure-by-default habits.
- →Drive a shift-left vulnerability detection program to identify and remediate vulnerabilities earlier in the software development lifecycle (SDLC).
- →Coordinate with DevOps for application security issues that cross between application and infrastructure layers
- →Support incident-response for product issues and feed lessons back into code, docs, and process.
- 5 + years in Application / Product Security
- Hands-on experience securing web applications and automating AppSec workflows.
- Familiarity with DevSecOps practices and container security & patching
- Experience with GitHub Actions, Python, TypeScript/JavaScript
- Clear, concise communicator who can translate risk for engineers
Nice to Have
~1 min read- Experience securing LLM workflows
- Experience with NIST Risk Management Framework
- Experience with software security at a U.S. defense contractor
- Active Security Clearance (or ability to obtain one) and willingness to travel onsite
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 1, 2026
- First seen
- September 1, 2026
- Last seen
- September 3, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- September 1, 2026
Signal breakdown
Please let Vannevarlabs know you found this job on Jobera.
3 other jobs at Vannevarlabs
View all →Explore open roles at Vannevarlabs.
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.