FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Staff Application Security Engineer
GeminiStaff Application Security Engineer at Gemini focusing on application security and AI-driven tooling for secure development practices. Collaborating with senior engineering leadership to enhance security measures.
Posted 7/21/2026full-timeNew York City • Florida, New York • 🇺🇸 United StatesLead💰 $168,000 - $240,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security, including threat modeling, secure code reviews, and penetration testing, while effectively communicating and collaborating across cross-functional teams. Proficient in designing and implementing security controls in regulated environments, with a strong focus on reducing application security risks.
Highest-signal resume keywords
Application Security Best PracticesThreat ModelingPenetration TestingCode Review Proficiency in Scala, Java, GoCross-Functional Communication
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Threat ModelingSecure Code ReviewPenetration TestingApplication Security ControlsScalaJavaGoPythonCode ReviewVulnerability Assessment
Soft Skills
Cross-Functional CollaborationCommunication
Industry Keywords
Financial ServicesFintechCryptoRegulated EnvironmentsOWASP Top 10
Tech Stack
Tools & technologiesGoJavaPythonScalaSDLC
About the role
Key responsibilities & impact- Own and evolve the Gemini Secure Software Development Lifecycle guardrails as an application security subject matter expert
- Lead architecture reviews, threat modeling, code reviews, and penetration testing for high-risk applications and services
- Design and build AI agents throughout the SDLC for automated threat modeling during design, AI-driven secure code generation and review, and reducing AppSec toil
- Create and deliver hands-on application security training to enable engineers at scale
- Participate in the Application Security on-call rotation and lead post-incident hardening
Requirements
What you’ll need- Proven ability to perform design reviews, threat modeling, secure code reviews, and penetration testing with an attacker mindset
- Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
- Deep code review proficiency in Scala, Java, Go or other common languages, plus hands-on experience in at least Python, Go, or similar for building. Comfortable reviewing production services written in other languages
- Experience implementing custom detection and prevention application security controls to eliminate application security issues beyond OWASP Top 10
- Familiarity with highly regulated environments (financial services, fintech, crypto, or equivalent) and ability to understand business objectives, business context, and security risk
- Strong cross-functional communication and collaboration (Security, Engineering, and Product)
- Typically 7-10+ years of experience or equivalent impact in application security, product security, or similar roles
Benefits
Comp & perks- Competitive starting pay
- A discretionary annual bonus
- Long-term incentive in the form of a new hire equity grant
- Comprehensive health plans
- 401K with company matching
- Paid Parental Leave
- Flexible time off