# Security engineer, application security

[Writer](https://gurify.com/jobs?q=Writer) · New York City, NY · Posted 2 weeks ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/WRITER/b07febfa-8c2e-479d-84a3-58cd7ccc1bc6)

## Job description

🚀 ABOUT WRITER

WRITER is where the world's leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we're proving it's possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER's end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company's data and fueled by WRITER's enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we're looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 ABOUT THE ROLE

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems powering some of the world's most recognizable brands. You'll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you'll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn't about saying "no"—it's about finding creative ways to say "yes, and here's how we do it securely." You'll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn't exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ WHAT YOU'LL DO

- Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

- Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

- Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

- Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

- Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

- Lead security assessments and penetration testing of WRITER's applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

- Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

- Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ WHAT YOU NEED

- Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you've worked in fast-growing startups or high-growth environments

- Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

- Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

- Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

- Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

- A builder's mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

- Alignment with WRITER's values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what's possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

 - *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

- Generous PTO, plus company holidays

- Medical, dental, and vision coverage for you and your family

- Paid parental leave for all parents (16 weeks)

- Fertility and family planning support

- Early-detection cancer testing through Galleri https://www.galleri.com/partner/writer

- Flexible spending account and dependent FSA options

- Health savings account for eligible plans with company contribution

- Annual work-life stipends for:

 - Wellness stipend for gym, massage/chiropractor, personal training, etc.

 - Learning and development stipend

- Company-wide off-sites and team off-sites

- Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don't make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER's Global Candidate Privacy Notice https://writer.com/legal/candidate-privacy-notice/.

**Live in Writer’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- AS [Security Engineer](https://gurify.com/job/security-engineer-at-assembledhq-280ac1c5d778) Assembledhq · New York City, NY · 4 days ago
- EV [Information Security Engineer (maternity cover)](https://gurify.com/job/information-security-engineer-maternity-cover-at-evoke-8ec4a93fd8ab) Evoke · Herzliya Pituach, Israel, IL · 3 weeks ago
- GO [Senior Security Engineer, Product Security](https://gurify.com/job/senior-security-engineer-product-security-at-goodleap-788ee656f8bd) Goodleap · Remote, United States · 3 weeks ago
- VO [Security Engineer, Compliance Focus](https://gurify.com/job/security-engineer-compliance-focus-at-volta-14a9fa68cf88) Volta · Palo Alto, CA · 7 weeks ago
- GI [Intermediate Software Engineer, Security Factory: Vulnerability ...](https://gurify.com/job/intermediate-software-engineer-security-factory-vulnerability-at-1d9ec8f2ea7f) Gitlab · Remote, United States · 4 weeks ago
- FA [Senior Enterprise Security Engineer](https://gurify.com/job/senior-enterprise-security-engineer-at-faire-74499d70d3ab) Faire · San Francisco, CA · 7 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security engineer, application security","description":"\u003Cp\u003E\u0026#128640; ABOUT WRITER\u003C/p\u003E\u003Cp\u003EWRITER is where the world\u0026#39;s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we\u0026#39;re proving it\u0026#39;s possible \u2013 through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER\u0026#39;s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company\u0026#39;s data and fueled by WRITER\u0026#39;s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.\u003C/p\u003E\u003Cp\u003EFounded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we\u0026#39;re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.\u003C/p\u003E\u003Cp\u003E\u0026#128208; ABOUT THE ROLE\u003C/p\u003E\u003Cp\u003EThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you\u0026#39;ll be building the security foundations that protect the AI systems powering some of the world\u0026#39;s most recognizable brands. You\u0026#39;ll work at the intersection of application security, AI infrastructure, and developer enablement\u2014partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.\u003C/p\u003E\u003Cp\u003EThe opportunity is massive: you\u0026#39;ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn\u0026#39;t about saying \u0026quot;no\u0026quot;\u2014it\u0026#39;s about finding creative ways to say \u0026quot;yes, and here\u0026#39;s how we do it securely.\u0026quot; You\u0026#39;ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn\u0026#39;t exist a few years ago.\u003C/p\u003E\u003Cp\u003EThis role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.\u003C/p\u003E\u003Cp\u003E\u0026#129464;\u0026#127995;\u200D\u2640\uFE0F WHAT YOU\u0026#39;LL DO\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EBuild security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one\u2014not after the fact\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOwn and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELead security assessments and penetration testing of WRITER\u0026#39;s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E\u2B50\uFE0F WHAT YOU NEED\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EMinimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems\u2014bonus points if you\u0026#39;ve worked in fast-growing startups or high-growth environments\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETechnical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices\u2014you know which tools to use and when automation beats manual review\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExcellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences\u2014you can explain why something matters and motivate teams to action\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA builder\u0026#39;s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks\u2014you understand that security enables the business, not blocks it\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E- Alignment with WRITER\u0026#39;s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what\u0026#39;s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)\u003Cbr /\u003E   \u003Cbr /\u003E   - *This role is open to Mid, Sr. and Staff level candidates\u003C/p\u003E\u003Cp\u003E\u0026#127849; Benefits \u0026amp; perks (US Full-time employees)\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EGenerous PTO, plus company holidays\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMedical, dental, and vision coverage for you and your family\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPaid parental leave for all parents (16 weeks)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFertility and family planning support\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEarly-detection cancer testing through Galleri https://www.galleri.com/partner/writer\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFlexible spending account and dependent FSA options\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHealth savings account for eligible plans with company contribution\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E- Annual work-life stipends for:\u003Cbr /\u003E   \u003Cbr /\u003E   - Wellness stipend for gym, massage/chiropractor, personal training, etc.\u003Cbr /\u003E   \u003Cbr /\u003E   - Learning and development stipend\u003C/p\u003E\u003Cul\u003E\u003Cli\u003ECompany-wide off-sites and team off-sites\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive compensation, company stock options and 401k\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWRITER is an equal-opportunity employer and is committed to diversity. We don\u0026#39;t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.\u003C/p\u003E\u003Cp\u003EBy submitting your application on the application page,  you acknowledge and agree to WRITER\u0026#39;s Global Candidate Privacy Notice https://writer.com/legal/candidate-privacy-notice/.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-application-security-at-writer-f9471c606c4a"},"url":"https://gurify.com/job/security-engineer-application-security-at-writer-f9471c606c4a","datePosted":"2026-09-04","validThrough":"2026-11-05T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Writer","sameAs":"https://jobs.ashbyhq.com/WRITER"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"US","addressLocality":"New York City"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United States","item":"https://gurify.com/jobs/united-states"},{"@type":"ListItem","position":3,"name":"Security engineer, application security","item":"https://gurify.com/job/security-engineer-application-security-at-writer-f9471c606c4a"}]}
```
