Staff Application Security Engineer

Thumbtack
United States
Workplace: RemoteFull timeUSD 249,900 - 323,400 annuallyFunction: CybersecurityExperience: 8+ yearsSkills: ["Ownership","Accountability","Mentoring","Analytical thinking","Communication"]

Own the long-term technical direction for application security at Thumbtack, building and driving roadmaps to remediate systemic risks across the application stack. Design secure-by-default architectures, standards, and paved paths, and create shared security tooling, libraries, patterns, and services that integrate with CI/CD, cloud infrastructure, and developer workflows. Lead cross-functional initiatives, threat modeling, and design reviews, mentor engineers, and support incident response and post-incident learning.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Thumbtack
Thumbtack
4 months ago

Staff Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 14 hours agoStatus: Live

Job Summary

Own the long-term technical direction for application security at Thumbtack, building and driving roadmaps to remediate systemic risks across the application stack. Design secure-by-default architectures, standards, and paved paths, and create shared security tooling, libraries, patterns, and services that integrate with CI/CD, cloud infrastructure, and developer workflows. Lead cross-functional initiatives, threat modeling, and design reviews, mentor engineers, and support incident response and post-incident learning.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own the long-term technical direction for application security and build prioritized roadmaps to drive remediation of systemic security risks.
  • •Design secure-by-default architectures, standards, and paved paths for engineering teams.
  • •Design and implement shared security tooling, libraries, patterns, and services to help teams ship quickly and safely.
  • •Embed security into CI/CD pipelines, cloud infrastructure, and developer workflows.
  • •Lead large cross-functional security initiatives (problem definition through delivery), including security design reviews and threat modeling; support incident response and post-incident learning.

Pay and Benefits

Salary: USD 249,900 - 323,400 annually

Key Requirements

  • •8+ years of experience in software engineering and application security, including secure coding practices and application security frameworks.
  • •Deep expertise in secure system design and architecture, including modern application security tools, patterns, and practices (e.g., threat modeling, secure design patterns).
  • •Proven track record leading large, cross-functional technical initiatives with sustained impact.
  • •Strong experience securing modern, cloud-native systems (AWS and/or GCP).
  • •Strong ownership and communication skills, with the ability to influence without authority and mentor others.
Experience:8+ yearsApplication securityCloud-nativeSecure system designThreat modelingSecure coding
Skills:OwnershipAccountabilityMentoringAnalytical thinkingCommunication
Tech Stack:AWSGCPCI/CDAuthentication and authorizationSecrets managementThreat modelingVulnerability discoverySecure design patterns

Company Brief

Thumbtack
Provides an online marketplace connecting local service professionals (home improvement, events, lessons, and more) with customers seeking quotes, reviews, and booking tools to hire vetted contractors and providers.
Industry: Online Marketplaces
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2008
WebsiteLinkedIn