Lead application security initiatives, integrate security practices into software development, manage vulnerabilities, and educate engineering teams on secure coding.
We are seeking a highly skilled Senior Application Security Engineer to serve as a Subject Matter Expert and expert technical contributor within our security team. This role is focused on driving the hands-on integration of the "Security by Design" philosophy across our product suite, ensuring our applications are resilient against modern threats. You will leverage deep technical expertise in software exploitation and defensive architecture to set secure standards, lead complex security projects, and mentor development teams on secure coding practices. The ideal candidate contributes significantly to technical strategy and architecture, focusing on building sustainable solutions that prevent security issues at scale.
Key Responsibilities:
- Application Security Strategy & Execution: Contribute to the strategic AppSec roadmap and lead the implementation of the Secure Software Development Lifecycle (SSDLC) and security standards for all software products.
- Security Architecture & Design: Lead deep-dive architectural reviews and hands-on threat modeling sessions for high-stakes product features. Define and implement secure development patterns (Authentication, Authorization, Encryption) for engineering teams to adopt.
- Vulnerability Management & Triage: Lead the response to critical software vulnerabilities, contribute to managing the Bug Bounty program, and drive automated workflows for prioritizing remediation based on exploitability and business risk.
- Secure Frameworks & Tooling: Design and implement internal security libraries and "paved roads" that allow developers to build securely by default. Oversee the selection, implementation, and tuning of AppSec tooling (SAST, DAST, SCA) to ensure high signal-to-noise ratios.
- Cross-Functional Technical Leadership: Serve as a core security subject matter expert for the Engineering organization. Lead technical initiatives to remediate security debt and mentor junior security engineers on advanced application defense.
- Modern Web & API Security: Apply expert-level knowledge of REST/GraphQL APIs, OAuth2/OIDC, and modern web frameworks to harden the application layer against sophisticated attacks.
- Incident Response (App Layer): Serve as a key technical responder for application-level security incidents, conducting forensic analysis of code execution and logic flaws to prevent recurrence.
- Evangelism & Training: Lead technical developer workshops and contribute to the "Security Champions" program to elevate security awareness and secure-coding practices across the engineering organization.
Required Qualifications:
- 6+ years of experience in software engineering or application security, with significant tenure as a subject matter expert.
- Software Engineering Foundation: Strong background as a professional software developer, with the ability to read, write, and debug code in multiple languages (e.g., Python, Go, Java, or JavaScript/TypeScript).
- Expert Threat Modeling: Proven ability to threat model complex, distributed systems and identify logic flaws that automated tools miss.
- Deep Vulnerability Expertise: Demonstrated mastery of identifying and mitigating the OWASP Top 10, business logic vulnerabilities, and advanced exploitation vectors.
- Tooling Mastery: Extensive experience implementing and customizing AppSec tools (e.g., Snyk, Checkmarx, Burp Suite, Semgrep) within enterprise-scale CI/CD environments (GitHub Actions, GitLab, etc.).
- Identity & Access Expert: Deep technical understanding of identity protocols (SAML, OAuth2, OIDC) and modern authorization models (RBAC, ABAC).
- Technical Project Leadership: Proven ability to lead complex technical projects and drive large-scale, cross-functional AppSec initiatives to completion.
Preferred Qualifications:
- Certifications: OSCP, OSWA, OSWE, or Burp Suite Certified Practitioner (BSCP).
- Programming: Strong programming skills in NodeJS, Python, and/or Go.
- Cloud Fluency: Experience securing applications specifically within AWS environments (Lambda, ECS/EKS, DynamoDB security).
- Compliance: Familiarity with mapping technical application controls to compliance frameworks like SOC 2, HIPAA, or PCI-DSS.
About FloQast:
FloQast is the leading Accounting Transformation Platform in accounting workflow automation created by actual former accountants for accountants. By streamlining and modernizing daily accounting tasks, FloQast helps teams collaborate more effectively and complete their work with greater efficiency and precision. This cloud-based, AI-powered software is trusted by over 3,000 accounting teams, including those at Snowflake, Twilio, Instacart, and The Golden State Warriors—and continues to grow. Our mission is to continuously elevate the accounting profession, enhancing both its practice and perception.
By applying for this position, you acknowledge and consent to FloQast’s collection, use, processing, and storage of your personal information and application materials in accordance with our privacy policy and applicable law, including, but not limited to, your resume, cover letter, contact information, employment history, references, and any other details or information provided during the application and interview process. Your information may be shared with hiring managers, HR personnel, and other employees involved in the hiring process, as well as authorized third-party service providers who assist with our hiring process. You have the right to access, correct or request the deletion of your personal information at any time. To exercise these rights, or for other questions related to our data practices, please contact us at [email protected]. Your consent is voluntary, but please note that providing this consent is necessary for us to process your application and consider you for employment opportunities. For more details, please see our privacy policy at https://www.floqast.com/legal/privacy-policy.
FloQast, Inc is committed to operating fair and unbiased recruitment procedures allowing all applicants an equal opportunity for employment, free from discrimination on the basis of religion, race, sex, age, sexual orientation, disability, color, ethnic or national origin, or any other classification as may be protected by applicable law. We aim to recruit the right people for the jobs we have to offer, and to assess applications on the basis of relevant skills, education, and experience. We welcome people of different backgrounds, experiences, abilities, and perspectives. We are an equal opportunity employer and strive to provide a professional and welcoming workplace for all employees.
Top Skills
AWS
Burp Suite
Checkmarx
Go
Java
JavaScript
Python
Semgrep
Snyk
Typescript
Similar Jobs at FloQast
Artificial Intelligence • Fintech • Software
Lead and manage a small team of engineers while contributing hands-on. Oversee team operations, technical mentorship, and ensure project quality and velocity.
Top Skills:
GoPythonTypescript
Artificial Intelligence • Fintech • Software
The Senior Data Warehouse Administrator will manage large-scale data warehousing, optimize performance, oversee data ingestion, and mentor junior staff while ensuring data governance and compliance policies are enforced.
Top Skills:
AirbyteApache IcebergAws GlueBashCdataFivetranMongoDBPythonS3SQLStitchTerraform
Artificial Intelligence • Fintech • Software
The Engineering Manager leads teams in delivering high-quality software solutions, coaches team members, manages hiring, and collaborates across departments.
Top Skills:
AWSExpressMongoDBNode.jsReact
What you need to know about the Kolkata Tech Scene
When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.

