Staff Application Security Engineer

Thumbtack

Remote
For c + idates living in san francisco / bay area,...
Remote
Secure system design and architecture
Modern application security tools
Threat modeling
Thumbtack is seeking a Staff Application Security Engineer to enhance its application security as the company scales and incorporates AI features. The ideal candidate should have extensive experience in software engineering and application security, with strong skills in secure system design and architecture

Job Summary

  • Own the long-term technical direction for application security across Thumbtack and drive remediation of systemic security risks.
  • Design secure-by-default architectures, standards, and paved paths for engineering teams, embedding security into CI/CD pipelines and developer workflows.
  • Partner with engineering and product leaders to prioritize security investments based on risk, impact, and business goals.

Matching Summary

Match Score: 85

Thumbtack is seeking a Staff Application Security Engineer to enhance its application security as the company scales and incorporates AI features. The ideal candidate should have extensive experience in software engineering and application security, with strong skills in secure system design and architecture.

Salary

For candidates living in San Francisco / Bay Area, San Jose, New York City, or Seattle metros, the expected salary range for the role is currently $249,900.00 - $323,400.00; For candidates living in Austin, TX or Washington DC metros or in California, Massachusetts, New Jersey, or Washington states, the expected salary range for the role is currently $225,300.00 - $291,500.00; For candidates living in all other US locations, the expected salary range for this role is currently $212,500.00 - $275,000.00

Skills & Requirements

Must-have

  • Secure system design and architecture
  • Modern application security tools
  • Threat modeling
  • Authentication and authorization
  • Secrets management
  • Vulnerability discovery and remediation

Nice-to-have

  • Balance pragmatism and rigor
  • Influence without authority
  • Raise the overall security bar

Key Requirements

  • 8+ years of experience in software engineering and application security
  • Strong experience securing modern, cloud-native systems (AWS and/or GCP)
  • Proven track record leading large, cross-functional technical initiatives

Work Rights

Not specified

Tailored Resume

Cover Letter