Senior / Staff Application Security Engineer

Suno
Boston, New York, Los Angeles, San Francisco
Workplace: OnsiteFull timeUSD 230,000 - 330,000 annuallyFunction: CybersecurityExperience: 6+ yearsSkills: ["Ownership","Builder mindset","Collaboration","Bar-raising communication"]

Own application security end to end by threat-modeling key features and services, driving remediation, and securing the application layer against injection, broken authentication/authorization, and insecure APIs. Build and run a secure SDLC with SAST/DAST, dependency and supply-chain protections, secrets management, and pre-production testing. Harden identity, session, and AI-specific surfaces (model/inference and prompt handling) while partnering with engineering to raise the security bar across the codebase.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Suno
Suno
1 week ago

Senior / Staff Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Own application security end to end by threat-modeling key features and services, driving remediation, and securing the application layer against injection, broken authentication/authorization, and insecure APIs. Build and run a secure SDLC with SAST/DAST, dependency and supply-chain protections, secrets management, and pre-production testing. Harden identity, session, and AI-specific surfaces (model/inference and prompt handling) while partnering with engineering to raise the security bar across the codebase.
Location: Boston, New York, Los Angeles, San Francisco
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Execute application security end to end by threat-modeling features/services and driving remediation of significant risks.
  • •Secure the application layer against key vulnerabilities, including injection, broken authentication/authorization, and insecure APIs.
  • •Build and run a secure SDLC with code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.
  • •Harden authentication, authorization, and session/identity handling across the product.
  • •Secure AI-specific application surfaces, including model/inference endpoints and prompt/input handling, and address generative-feature vulnerability classes.

Pay and Benefits

Salary: USD 230,000 - 330,000 annually
Equity and Bonus:Equity
Perks:Equity401kHealth InsuranceDentalVisionPaid LeaveParental LeaveLearning BudgetCommuter BenefitsMeal Allowance

Key Requirements

  • •6+ years in security engineering with deep, hands-on application security expertise.
  • •Strong command of vulnerability classes affecting incidents, including code, API, and authorization design.
  • •Built AppSec practices and secure-SDLC tooling, not only operated existing ones.
  • •Fluent in modern application stacks and comfortable with AWS.
  • •Able to write and ship production-quality code and raise security standards without becoming a blocker.
Experience:6+ yearsApplication securitySecurity engineeringAWSGenerative AILLM threat modeling
Skills:OwnershipBuilder mindsetCollaborationBar-raising communication
Tech Stack:AWSThreat modelingSecure SDLCCode review guardrailsSASTDASTDependency securitySupply-chain securitySecrets managementPre-production testingInjectionAuthenticationAuthorizationSession handlingIdentity handlingAI/LLM threat classesPrompt handlingModel endpointsInference endpoints

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Suno
Develops AI-driven music generation tools that enable users to create original songs, instrumentals, and audio content from text prompts or melodies using generative models and creative workflows for musicians and creators.
Industry: Music Industry
Company Size: Small (11 to 50 employees)
Growth: Early Stage Startup
Founded: 2023
Website