Security Engineer - Application Security (Senior)
WFA Digital Insight
Cogent Security’s senior security engineer role is built around a product‑first mindset that blends AI innovation with hands‑on engineering. The team is not just adding security as an afterthought; engineers are expected to embed threat modeling, secure design reviews, and automated testing directly into the development pipeline. What sets this opportunity apart is the chance to influence a nascent AI cyber‑taskforce—an autonomous system that tackles emerging threats in real time. Candidates will work closely with product owners and engineers, acting as the security conscience of the platform while shaping tooling that scales across the codebase. For those comfortable navigating both strategic decisions and low‑level code, the position offers a rare blend of ownership, impact, and exposure to cutting‑edge AI security challenges.
Job Description
ABOUT COGENT Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity. AI has fundamentally changed how attacks happen, allowing malicious actors to operate at unprecedented speed and scale. Cogent’s "AI Taskforce" assesses petabytes of enterprise data to remediate these issues before critical breaches occur. To stay at the cutting edge, we blend frontier research with real-world execution. Alongside our core product work, Cogent Research serves as our applied AI lab, providing the research horsepower needed to make truly agentic security workflows a reality. Since coming out of stealth, Cogent has experienced rapid growth. We partner with Fortune 500 companies to secure some of the most complex production environments in the world. We’re backed by Greylock and we’ve built a team with the best minds in applied AI. Our team is comprised of people from: - Top universities like Stanford, Berkeley, Penn, Duke, Carnegie Mellon, Waterloo - Preeminent research labs like Deepmind and SAIL - Unicorn, high-growth companies like Scale AI, Databricks, Stripe, Tesla, Coinbase - World class cybersecurity experts from Wiz, Abnormal AI, Zscaler ABOUT THE ROLE We're hiring a Senior Security Engineer, Product Security to own the security of the software we build. You'll partner closely with engineering to embed security into the Software Development Lifecycle (SDLC), keep our dependencies and supply chain safe, and make sure the product our customers trust is built on a secure foundation. You’ll also have the chance to influence our product, as an internal SME and early security user, your feedback loop directly shapes what we ship. WHAT YOU’LL DO - Embed security into the software development lifecycle: threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt - Own application security testing - code review, SAST/DAST, and triage - and drive issues to remediation rather than just filing them - Harden our software supply chain: dependency verification, safe dependency management, and CI/CD pipeline security - Build and automate security tooling and guardrails so security scales with engineering, not against it - Serve as the internal security SME on product and workflow decisions, and as an early user of what we build - Partner across all teams on architecture and design so security is a default, not an afterthought WHAT WE'RE LOOKING FOR - 5+ years of extensive security engineering experience within product / application security, upholding the highest Trust standards - Strong hands-on engineer who ships - you produce and automate, you don't just manage process - Strong software engineering skills; comfortable working in code across the stack (e.g. Python, Go, Typescript, and/or similar) - Depth in application/product security: secure SDLC, threat modeling, code scanning, and supply-chain / dependency security - Fluency with the modern AI landscape and how it’s influencing the security picture - staying up to date with the rapidly changing environment - Able to flex up and down: strategic when it matters, in the weeds when it counts - Comfortable being an early security hire at a startup - high ownership, ambiguity, and direct impact BONUS POINTS - Experience securing AI/ML products or agentic systems - Background contributing to developer-enablement or security-champions programs - Prior experience as an early security hire or building an AppSec function from scratch FOR CALIFORNIA BASED APPLICANTS The standard base salary range for this position is $100,000 - $300,000 annually. Compensation offered will be determined by factors such as location, job level, job-related knowledge, skills, and experience. Certain roles may be eligible for variable compensation, equity, and benefits. We are committed to building an inclusive and diverse company. We do not discriminate based on gender, ethnicity, sexual orientation, religion, civil or family status, age, disability, or race.
How to Stand Out
- Highlight any experience you have automating security checks in CI/CD pipelines; concrete examples stand out.
- Prepare a brief walk‑through of a past threat‑modeling session you led, focusing on outcomes and remediation speed.
- Bring a portfolio of code reviews or security tooling you built—show tangible artifacts, not just resume bullets.
- Expect interviewers to probe both strategic risk assessments and low‑level code details; be ready to switch contexts quickly.
- Research Cogent’s AI cyber‑taskforce publicly available materials to demonstrate genuine interest and domain awareness.
- When discussing salary, emphasize the value of equity in a high‑growth startup and ask about the vesting schedule.
- Watch for red flags such as unclear reporting lines or lack of defined security governance; ask clarifying questions during the interview.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.