Bonterra is a company focused on increasing the giving rate in the social good sector through technology and expertise. They are seeking a Senior Application Security Engineer to partner with development teams, drive vulnerability remediation, and build AI-powered workflows to enhance security practices.
Responsibilities:
- Report directly to the Head of Application Security
- Build, extend, and operate AI-powered agents and workflows that automate vulnerability remediation tasks
- Drive vulnerabilities to closure by working directly with development teams
- Act as a security champion embedded across Bonterra's engineering organizations, building trust and normalizing secure development practices
- Triage and prioritize findings from SAST, SCA, IaC scanners, filtering noise and surfacing what needs immediate attention
- Integrate security validation into CI/CD pipelines and developer workflows
- Support SOC 2, PCI-DSS, HIPAA, and other audits as needed
Requirements:
- Demonstrated experience building AI agents, LLM-powered workflows, or automated pipelines
- Working knowledge of software vulnerability classes, how CVEs are assessed, and what good remediation looks like
- Understand how software gets built and where security integrates into the development process
- You can translate a security finding into language a developer can act on without a security background
- An extensive track record of building AI agents to solve real operational problems that accelerate outcomes
- Experience with SAST/SCA platforms at an engineering team level
- Prior work building or running a security champion program
- Familiarity with AWS security services or cloud environment security
- Knowledge of application security frameworks -- OWASP Top 10, NIST, CVSS scoring
- Previous software development experience