Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Application Security Engineer image - Rise Careers
Job details

Application Security Engineer

About Onebrief

Onebrief is collaboration and AI-powered workflow software designed specifically for military staffs. By transforming this work, Onebrief makes the staff as a whole superhuman - meaning faster, smarter, and more efficient.

We take ownership, seek excellence, and play to win with the seriousness and camaraderie of an Olympic team. Onebrief operates as an all-remote company, though many of our employees work alongside our customers at military commands around the world.

Founded in 2019 by a group of experienced planners, today, Onebrief’s team spans veterans from all forces and global organizations, and technologists from leading-edge software companies. We’ve raised $123m+ from top-tier investors, including Battery Ventures, General Catalyst, Insight Partners, and Human Capital, and today, Onebrief is valued at $1.1B. With this continued growth, Onebrief is able to make an impact where it matters most.

Security Clearance, Location, and Onsite Notice:

This role is remote. The role may require occasional (once per quarter or less) on-site activities at customer locations.

Must be a US Citizen, eligible for a Secret Security Clearance. Active Secret or Top Secret Clearance is a plus, SCI eligibility is a plus.

About The Role

We are hiring an Application Security Engineer to join our Infrastructure & Security team. You’ll report to our Director of Infrastructure and work closely with fellow SREs, Software Engineers, DevOps Engineers, Platform Engineers, Customer Relations, and Cybersecurity Analysts.

You will be helping identify, triage and fix security issues within the Onebrief application and related platform and deployed infrastructure.

About You

You are a security-minded individual who knows that vulnerabilities in modern software are an existential business risk. Maybe you love reading incident reports, and perhaps you even participate in security conferences like DefCon or OWASP meetups. Ideally, you have experience in a related field like software engineering, DevOps or systems administration. You are familiar with modern cloud-native technologies like Kubernetes and have experience with software development. Maybe you have experience with game cheat development/detection, bug bounties, or maybe you come from a traditional enterprise security background.

What You’ll Do

You will own the security and compliance posture of our software products and platform. You will do this by:

  • Find Vulnerabilities in our Software: Bring an attacker’s mindset to review PRs, perform code audits, and utilize static analysis to identify vulnerable code patterns that can be exploited by adversaries. Use dynamic analysis, fuzzers and code reviews to find weaknesses in our codebase and work with developers to patch them.

  • Fix Vulnerabilities Across the Full Stack: Think like an adversary to find, fix, prevent or patch vulnerabilities from browser to kernel. Utilize vulnerability scanners to find unpatched components, and identify configuration errors that could expose our deployments to an attacker. Work with platform engineers to harden our customer environments and utilize best practices. Advise on network configuration, identity and access management and infrastructure security.

  • Improve the Security Posture of Infrastructure: Review identity and access management, logging, auditing, monitoring to help craft a layered defense for our corporate infrastructure and customer environments. Work with Cybersecurity analysts to help ensure compliance with corporate/Federal standards like SOC II, NIST and FedRamp Moderate/High.

  • Make the Team Stronger: Mentor other engineers on best security practices, share news of vulnerable libraries and compromises, engage with community on active threats and trends in exploit development, malware, etc. Work to improve processes to shift security “left” and identify vulnerabilities earlier in the design, development and deployment of our software.

What we look for:

Experience & collaboration

  • 5+ years of experience in Application Security, Cybersecurity Engineering, Software Engineering or a related field, preferably with first-hand experience ensuring security in high-compliance environments like PCI DSS, HIPAA or NIST.

  • U.S. citizenship required, security clearance greatly desired.

  • A strong understanding of Linux, containerization and orchestration, and virtual machines

  • Networking fundamentals: core protocols and secure configurations.

  • A deep understanding of incident response processes, with experience conducting thorough root cause analyses and driving continuous improvement

  • Clear, concise writing; strong documentation habits and async communication.

  • Core skills and technologies: Javascript/Browser security, Network Security, Firewalls, Intrusion Detection, Static Analysis, Dynamic Analysis, Container Scanning, Kubernetes, Docker, Helm, Ansible, Terraform, Linux, AWS, DoD compliance, Monitoring and Observability tools.

Bonus points (nice to have)

  • Experience with compliance frameworks/processes (RMF, STIGs/SRGs, PCI DSS, HIPAA, ICD 503).

  • Security considerations/design for air-gapped environments.

  • Active Security+ or another DoD 8570.01-approved security credential, or the ability to obtain the valid credentials within 3 months of employment.

  • Must-Have Skills and Qualifications:

    • Required education, certifications, or licenses.

      • N/A

    • Required years of experience and relevant industries.

      • 5+ years experience in Cybersecurity, Software Engineering and/or DevOps

    • Essential technical or soft skills.

      • Familiarity with DevOps practices, CI/CD

      • Familiarity with security tooling such as Static & Dynamic Analysis (SAST/DAST)

      • Familiarity with networking, web protocols

      • Working grasp of PKI, TLS and cryptographic primitives

  • Preferred Skills and Qualifications (if any):

    • Additional skills or experience that would be advantageous.

      • JavaScript Experience

      • Security+ Certification or other IAT Level II equivalent

      • CSSLP or CISSP

      • Familiarity with DoD Software Lifecycle, RMF/ATO, STIG

      • Pentesting / Red Team experience

      • Familiarity with web authentication/authorization technologies such as SSO, SAML, OIDC, JWT, etc.

      • Experience with Kubernetes and modern Cloud-Native deployment strategies

Onebrief Glassdoor Company Review
5.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
Onebrief DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Onebrief
Onebrief CEO photo
Unknown name
Approve of CEO

Average salary estimate

$165000 / YEARLY (est.)
min
max
$140000K
$190000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Character Bio Hybrid No location specified
Posted 20 hours ago

Character Biosciences is hiring a remote Software Engineer to build and maintain cloud-native data platform tools that connect deidentified clinical, imaging, and genomic data to downstream data science and clinical operations.

MLabs Hybrid No location specified
Posted 13 hours ago

Build and own high-throughput DeFi trading and yield systems as a Senior Fullstack Engineer at a crypto-native startup backed by institutional investors.

Photo of the Rise User
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Vision Insurance
Family Medical Leave
Paid Holidays

Senior backend engineer sought to build scalable, reliable backend services for LaunchDarkly’s Release Monitoring and observability products, helping teams ship features faster and safer.

Photo of the Rise User
Posted 15 hours ago
Inclusive & Diverse
Feedback Forward
Collaboration over Competition
Growth & Learning

Lead the design and implementation of a production-grade network gateway/load balancer to route long-lived, low-latency inference traffic for cutting-edge AI models at OpenAI.

Photo of the Rise User
Posted 48 minutes ago
Dental Insurance
Disability Insurance
Vision Insurance
Equity
Paid Time-Off
Medical Insurance
Mental Health Resources
Paid Holidays
Company Retreats

Lead the design and delivery of AI-assisted engineering tools and platform services to measurably increase developer velocity, quality, and reliability at Hims & Hers.

Photo of the Rise User
Ketch Hybrid San Francisco, California
Posted 2 hours ago

Ketch is hiring a Senior Frontend Engineer to own and evolve client-side JavaScript SDKs and tags that power privacy, consent, and data governance at scale.

Photo of the Rise User

Element is hiring a Senior Full Stack Developer to lead development of secure, scalable AI-integrated web applications for a state government modernization program.

Photo of the Rise User
Posted 14 hours ago
Customer-Centric
Mission Driven
Inclusive & Diverse
Rise from Within
Diversity of Opinions
Work/Life Harmony
Growth & Learning
Transparent & Candid
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Child Care stipend
Paternity Leave
WFH Reimbursements
Flex-Friendly
Dental Insurance
Vision Insurance
Life insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Military leave

Senior full-stack engineer role at NVIDIA focused on architecting scalable cloud-native web applications, driving company-wide cloud optimization, and mentoring engineering teams.

Posted 21 hours ago

Experienced Python backend Tech Lead needed to own and evolve an AWS-based data platform, guide engineering delivery, and drive architecture for a faith-focused analytics SaaS product.

Posted 22 hours ago

Lead Counsel Health's engineering organization as a hands-on SVP driving architecture, hiring, and delivery of an AI-native care platform that scales clinical impact.

Posted 14 hours ago

Experienced ServiceNow Developer needed to build and maintain ITSM solutions, integrate systems, and support ServiceNow modules for a U.S.-based government/agency contract.

Photo of the Rise User

SalesCloser.ai is hiring a Senior Python Developer to design scalable backend systems and APIs for its conversational AI SaaS platform in a fully remote role.

Photo of the Rise User
Domino's Hybrid 30 Frank Lloyd Wright Dr, Ann Arbor, MI 48105, USA
Posted 18 hours ago

Domino’s Technology team is hiring a Software Developer to build and maintain reporting tools and data visualizations using C#, .NET, TypeScript and SQL at the Ann Arbor location.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
November 4, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!