Senior Application Security Engineer [Remote-US]
Quanata is on a mission to help ensure a better world through context-based insurance solutions. We are an exceptional, customer-centered team with a passion for creating innovative technologies, digital products, and brands. We blend Silicon Valley talent and cutting-edge thinking with the long-term backing of leading insurer State Farm.
About the team
From data scientists and actuaries to engineers, designers, and marketers, we’re a world-class team of tech-minded professionals from some of the best companies in Silicon Valley and around the world. We’ve come together to create the context-based insurance solutions and experiences of the future. We know that the key to our success isn't just about nailing the technology—it’s hiring the talented people who will help us continue to make a quantifiable impact.
Responsibilities
- Partner with one product portfolio to facilitate overall product security management, with emphasis on AI/ML-specific security concerns and cross-functional work with data science teams
- Perform security design reviews and threat modeling on APIs, web features, and service integrations, including integrating SAST, SCA, and DAST tools into CI/CD pipelines
- Support secure development practices across security champions and engineering
- Review source code and deployment configurations for security vulnerabilities
- Collaborate with developers to triage, fix, and validate vulnerability findings
- Participate in cross-functional incident response and remediation planning
- Draft and maintain AppSec guidance for engineering teams and security champions
- Contribute to security awareness and enablement across the engineering org
- Develop AppSec-related integrations and deployments of automation solutions (ASVS scanning, Burp Suite Enterprise)
- Support application security integration reviews, SaaS security assessments, and open-source software reviews
Requirements
- Bachelor’s degree or equivalent relevant experience
- 6 - 8 years of experience in application security or full-stack development with security expertise
- Strong understanding of secure coding in JavaScript/TypeScript, Node.js, and web standards
- Familiar with application risk and vulnerabilities (OWASP Top 10, API Security, SSRF, etc.)
- Experience with code scanning tools (e.g., CodeQL, Semgrep, SonarQube, Snyk)
- Comfortable reading and debugging complex codebases across the stack
- Clear and thoughtful communicator with the ability to guide engineers at all levels
- Working concepts of offensive security testing such as pentesting or bug bounties
Nice to have
- Experience with GraphQL security
- Participation in security champions programs or secure SDLC rollouts
- Contributions to open-source security tooling
- Familiarity with infrastructure-as-code and container security
Pay
Salary: $220,000 to $350,000
Benefits
- Medical, dental, vision, life insurance, and supplemental income plans for you and your dependents
- Headspace app subscription
- Monthly wellness allowance
- 401(k) Plan with a company match
- One-time $2,000 payment for in-home office equipment and furniture
- MacBook Pro provided
- Four weeks of PTO in the first year of employment
- Twelve weeks of fully paid parental leave for new parents (birthing and non-birthing)
- Up to $5,000 each year for professional learning, continuing education, and career development
- LinkedIn Learning subscriptions
- Access to coaching opportunities through BetterUp
Schedule
- Remote-first company; work from anywhere in the U.S. (excluding territories)
- Core meeting hours: 9 AM - 2 PM Pacific Time
- Occasional travel may be requested or encouraged but is not required