waypointjobs

Vannevar Labs

Application Security Engineer

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Vannevar is a defense technology company building AI to deter our adversaries. In the 21st century, conflict moves at algorithmic speed and foresight equals firepower. Our agentic AI is purpose-built to compete with China—from cross-Strait conflict to gray zone coercion. Trained on the most mission-relevant datasets in defense, our technology models adversary behavior, simulates campaigns, and recommends the best course of action to decision makers. Our AI systems are some of the most trusted in the industry and actively used on the front lines of the Indo-Pacific to keep the peace and save lives.

Exceptional technology starts with exceptional people. Vannevar is a small agile team combining world-class engineers with veteran strategists who bring deep expertise in defense and tradecraft. We’re building a company defined by mission impact, user empathy, and disciplined growth. In just three years, we grew from $3M to $80M in ARR, achieved early profitability, and reached unicorn status—proving that disruption doesn’t require an ego, and staying power doesn’t mean standing still.

About the role

As an Application Security Engineer, you will help build security into our SaaS platform, ensuring we can quickly ship secure features to our customers. You will partner with software, DevOps, and platform teams, while coordinating with audit partners, to embed threat modeling, automated SAST/SCA/DAST, and rapid vulnerability response into every stage of our SDLC. Your work will be pivotal in protecting customer data, meeting compliance milestones, and scaling our security posture as the company grows.

What you'll do

Implement and deploy enterprise standard SAST, SCA, secrets-scan, DAST, and container/IaC checks in CI/CD

Embed with development teams to run threat models, review critical PRs, and coach secure-by-default habits.

Drive a shift-left vulnerability detection program to identify and remediate vulnerabilities earlier in the software development lifecycle (SDLC).

Coordinate with DevOps for application security issues that cross between application and infrastructure layers

Support incident-response for product issues and feed lessons back into code, docs, and process.

What you should have

5 + years in Application / Product Security

Hands-on experience securing web applications and automating AppSec workflows.

Familiarity with DevSecOps practices and container security & patching

Experience with GitHub Actions, Python, TypeScript/JavaScript

Clear, concise communicator who can translate risk for engineers

Nice to have

Experience securing LLM workflows

Experience with NIST Risk Management Framework

Experience with software security at a U.S. defense contractor

Active Security Clearance (or ability to obtain one) and willingness to travel onsite

Benefits:

Health, dental, and vision insurance

100% remote - work from anywhere in the US

401k matching

Mental benefits

Flexible work environment - you manage your workday

Pet and child care reimbursement during travel

Unlimited PTO

Compensation

The salary range for this position is $160,000 - $210,000 + equity + 401K match. Within the range, individual pay is determined by experience, relevant education, and/or training.

Vannevar is an equal opportunity employer, and qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

We encourage candidates from all backgrounds to apply, even if you don't feel like you're a perfect fit. If you're passionate about contributing to our mission, we'd love to hear from you!

IMPORTANT NOTICE

We are committed to protecting the privacy of all applicants. Official emails from the company will come from an @vannevarlabs.com domain. Under no circumstances will a legitimate representative from our company contact you to request passwords, financial information, or other sensitive personal data. Please be vigilant of potential scams.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job