Application Security Engineer II
About the Company
Omnissa is a leading technology company dedicated to delivering innovative software solutions across various platforms, including cloud-native, mobile, and endpoint management systems. With a focus on security, scalability, and user-centric design, Omnissa continually pushes the boundaries of technology to meet the evolving needs of its global customer base. The company fosters a collaborative and inclusive work environment that values diversity, professional growth, and technological excellence. Committed to integrity and excellence, Omnissa strives to be at the forefront of the industry by integrating cutting-edge security practices into all aspects of its product development lifecycle.
About the Role
The Application Security Engineer – Staff 2 role is a senior, hands-on technical leadership position within Omnissa’s Product Security team. This role is pivotal in defining and executing the security strategy across Omnissa’s diverse product portfolio, which includes Unified Endpoint Management, Virtual Apps and Desktops, and cloud-native and mobile platforms. As a key influencer, you will set technical standards, guide architecture decisions, and implement best practices to elevate the organization's security posture. This leadership role emphasizes influence through expertise, standards, and strategic initiatives rather than direct management of personnel. The ideal candidate will possess a deep understanding of application security, threat modeling, secure architecture, and code review processes, with a passion for solving complex security challenges in a fast-paced environment.
Qualifications
- 12+ years of hands-on application security experience with a proven track record of technical influence and leadership
- Deep knowledge of application security vulnerabilities, mitigation techniques, and risk prioritization based on business impact
- Expertise in threat modeling, secure design, and security architecture for distributed, cloud-native, and mobile systems
- Proficiency in Java or C++, with the ability to review and reason about production code
- Broad security expertise across application, system, cloud, and mobile domains
- Experience driving technical change, mentoring engineers, and elevating security standards across teams
- Excellent documentation, communication, and stakeholder influence skills
- Self-motivated, adaptable, and capable of working independently in ambiguous environments
- Practical mindset with the ability to develop both short-term and long-term strategic solutions
- Preferred: Experience testing agentic AI systems and leveraging AI tooling in security workflows
- Preferred: Experience building automation solutions to scale security processes
- Preferred: Background as a pen tester for multi-tenant SaaS providers
- Educational background: Bachelor’s degree in Computer Science or related field, or equivalent professional experience
Responsibilities
- Define and lead the technical security standards, patterns, and guardrails adopted by engineering teams at scale
- Embed threat modeling practices into the development lifecycle for distributed, cloud-native, and mobile architectures
- Develop security architecture reference designs to streamline security reviews and reduce repetitive assessments
- Identify architectural risks early and influence product roadmaps and design decisions pre-implementation
- Conduct manual code reviews and application security testing across Java and C++ codebases, translating findings into actionable guidance
- Scale code review efforts using AI-assisted analysis and custom CodeQL queries tailored to Omnissa’s vulnerability patterns
- Perform variant analysis to ensure consistent remediation of vulnerability classes across codebases
- Triage and validate externally reported vulnerabilities, assessing exploitability, severity, and impact, and drive remediation
- Translate individual security findings into systemic recommendations addressing root causes
- Develop and refine the Secure Development Lifecycle (SDL), driving measurable improvements and iterative enhancements
- Enhance the feature security review process, shifting security considerations earlier into design phases and across teams
- Strengthen the product penetration testing program, defining scope, methodology, and ensuring findings lead to systemic fixes
- Build and expand the security champions program, mentoring engineers and creating training resources to elevate security awareness
- Establish metrics to measure the effectiveness of security initiatives and communicate progress to leadership
Benefits
- Competitive salary range of USD $220,000 – $270,000 annually, with potential eligibility for performance-based bonuses
- Comprehensive health insurance plans
- 401(k) retirement plan with company matching contributions
- Paid time off and holiday leave
- Employee ownership opportunities
- Disability insurance and other wellness benefits
- Professional development and growth opportunities
- Flexible work arrangements including hybrid and remote options