Senior Application Security Engineer
- Hiring from
- India
- Work type
- Remote
- Posted
Show job descriptionHide job description
Overview
Senior Application Security Engineer
One Identity · Information Security, Attack Surface
Senior individual contributor · India · Reports to the Director of Information Security
Why this role exists
Our products are the access control layer for the companies that buy them. Identity Manager, Active Roles, Safeguard and OneLogin decide who gets into everything else a customer runs. That sets the security bar for our code higher than it sits at most software companies, and it's the reason this role works inside engineering rather than alongside it.
Much of what we build is deployed by customers in their own datacenters. When a defect ships, remediation moves at their upgrade cadence, not ours. That changes where the effort belongs: a design flaw caught in a threat model costs a conversation, and the same flaw caught after release costs a coordinated disclosure and a year of upgrade calls. This role is funded to move security earlier.
We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role is the security voice in the product organization. Scope comes from what you build into the development lifecycle and from what engineering chooses to adopt.
What you'll do
Design it right
- Threat model the things that matter: authentication and session handling, privilege elevation paths, connector and integration boundaries, tenant isolation in hosted offerings, and cryptographic and secrets handling. You choose where the depth goes.
- Set security requirements early enough to shape a design instead of contesting one. Engineering teams should meet you at the architecture stage, not at the release gate.
- Give product and engineering leadership a defensible read on which risks are worth carrying, in language a release decision can be made from.
Work in the code
- You'll hold commit access to product repositories. A dependency bump, a patched library, a fix in the code path that produced the finding: submit it, review it, and pair with the engineer who owns that module. PRs, not tickets.
- Own static analysis, dependency scanning, and dynamic testing across the product lines. Tune them until the signal is worth the interruption, and route findings to the team that can act on them.
- Raise the ceiling on secure coding across a large .NET and Java codebase: patterns, libraries, and reference implementations that make the safe approach the convenient one, plus the review depth to know when they're being used correctly.
- Take a position on AI-assisted development. Engineering is generating code with it, and someone needs to decide what review that code gets, where automated remediation is trusted to open a pull request, and how we verify what it changed.
Stand behind what ships
- Own product vulnerability response end to end: intake from researchers and customers, triage across affected versions, coordinated disclosure, CVE handling, and the advisory customers actually read.
- Turn penetration test and bug bounty findings into fixes and into the systemic change that prevents the next one. Recurrence is the signal that a control is missing, not that a bug was missed.
- Own software composition analysis and SBOM generation across the product lines, including the license and provenance data Legal and customers depend on.
- Make product security evidence available on demand. Customer questionnaires, security reviews, and certification work all draw on the same underlying facts, and they should be produced from one source.
What we're looking for
Required
Six or more years in software engineering or security, with at least three focused on application or product security. Equivalent depth counts.
- Application security experience on a product that customers deploy and operate themselves, with the release and disclosure realities that come with it.
- Code-level fluency in C# and .NET, and enough range to be useful in a Java codebase. You read and write production code, not just findings.
- Hands-on work with AI-assisted development or AI-enabled security tooling within the last six months, and a considered view on where it belongs in a review pipeline.
The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us.
Also matters: threat modeling at design time with engineering in the room; static, dynamic and composition analysis tooling and the judgment to tune it; identity and authentication protocols including OAuth, OIDC, SAML and SCIM; coordinated vulnerability disclosure and CVE handling; secure code review depth in web and API surfaces; the ability to hold a position with senior engineers and change it when they're right.
Helpful: SBOM standards and license compliance, cryptographic review, security champions programs, PCI DSS or FedRAMP applied to a product rather than a company, prior time as a product engineer.
What you should know going in
This role is embedded in engineering by design, with the access to prove it. You'll work across every product line, which means breadth before depth and a constant judgment call about where your attention is worth most. The work is visible to engineering leadership and it reaches customers directly through what ships and what we're able to tell them. If you want to be measured by what got fixed rather than what got filed, this is that seat.
Company Description
One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward.
With team members around the globe, we intend to continue to grow revenues and add value to customers.
When you join our team, you will have the opportunity to build and develop products at a scale few others can provide.
Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses.
Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment.
Why work with us?
Life at One Identity means collaborating with dedicated professionals with a passion for technology.
When we see something that could be improved, we get to work inventing the solution.
Our people demonstrate our winning culture through positive and meaningful relationships.
We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential.
Our team members’ health and wellness is our priority as well as rewarding them for their hard work.
One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment.
All employment decisions at One Identity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate.
One Identity will not tolerate discrimination or harassment based on any of these characteristics. One Identity encourages applicants of all ages.
Come join us.
Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be One Identity employees if they have an email address ending in @oneidentity.com.