Quanata is on a mission to help ensure a better world through context-based insurance solutions. The Senior Application Security Engineer will serve as the primary partner for web and backend engineering teams, embedding security best practices throughout the software development lifecycle and addressing complex security challenges across product surfaces.
Responsibilities:
- Partner with one product portfolio to facilitate overall product security management, emphasis on AI/ML-specific security concerns and cross-functional work with data science teams
- Perform security design reviews and threat modeling on APIs, web features, and service integrations, including integrating SAST, SCA, and DAST tools into CI/CD pipelines
- Support secure development practices across security champions and engineering
- Review source code and deployment configurations for security vulnerabilities
- Collaborate with developers to triage, fix, and validate vulnerability findings
- Participate in cross-functional incident response and remediation planning
- Draft and maintain AppSec guidance for engineering teams and security champions
- Contribute to security awareness and enablement across the engineering org
- Develop AppSec related integrations and deployments of automation solutions (ASVS scanning, burpsuite enterprise)
- Support application security integration reviews, saas security assessments, oss reviews
Requirements:
- Bachelor's degree or equivalent relevant experience
- 6 - 8 years of experience in application security or full-stack development with security expertise
- Strong understanding of secure coding in JavaScript/TypeScript, Node.js, and web standards
- Familiar with application risk and vulnerabilities (OWASP Top 10, API Security, SSRF, etc.)
- Experience with code scanning tools (e.g., CodeQL, Semgrep, SonarQube, Snyk)
- Comfortable reading and debugging complex codebases across the stack
- Clear and thoughtful communicator with the ability to guide engineers at all levels
- Experience with GraphQL security
- Participation in security champions programs or secure SDLC rollouts
- Contributions to open-source security tooling
- Familiarity with infrastructure-as-code and container security