Sentry logo

Security Engineer (Application Security)

Sentry

On-siteSan Francisco, California, United States {{REMOTE}}mid$155k–$400kPosted 11h ago

Job description

  • The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset

  • We work at a company with a strong developer culture, building a product that millions of developers genuinely love and rely on. That context shapes everything about how we operate

  • As a Security Engineer on this team, you’ll work across application and platform security domains

  • You’ll contribute to the practices that keep Sentry secure as we grow: security reviews, threat modeling, vulnerability management, and embedding secure coding practices into an engineering organization that cares about doing things right

  • You’ll partner closely with product and engineering teams to influence how features are designed and built from the start. You will work as a technical collaborator who helps make the secure path the obvious one. As Sentry expands our agentic product capabilities and development practices, you’ll also find yourself at the frontier of a new set of security challenges

  • Support and help mature Sentry’s security review program. From secure code review, to architecture review, and threat modeling. You’ll help build the processes, tooling, and culture which make security a natural part of how we ship and operate

  • Contribute to mature vulnerability management practices. Intake, triage, prioritization, remediation tracking, and support of our bug bounty and responsible disclosure program

  • Advocate for secure-by-design principles. Partner with engineering and product teams to embed security early in the development lifecycle and integrate security tooling into developer and CI/CD workflows

  • Validate and reproduce application and infrastructure security findings. Scanning, manual testing, and supporting penetration testing and vulnerability validation across Sentry’s application, SDKs and cloud-based platform

  • Help evaluate and respond to emerging threats relevant to application security at Sentry. We build and operate a complex application and cloud environment, including the novel attack surface introduced by Sentry’s agentic product features and AI-assisted engineering practices

Benefits

  • Competitive Compensation + Equity

  • Medical, Dental, Vision Insurance

  • Commuter Stipend

  • Professional Development Stipend

  • Health & Wellness Benefits

  • Charitable Matching Program

  • Flexible PTO

  • Paid Parental Leave

  • 401k Plan- Thrive with ownership and want more of it, you prefer to drive work end-to-end, and you’re energized by the autonomy — and the mentorship — that comes with being on a small, high-trust team

  • Love working in a developer-forward culture where your colleagues are builders who care deeply about code quality and customer satisfaction

  • Enjoy operating cross-functionally, building relationships, and influencing with technical expertise as you grow into shaping how security gets done across a fast-moving engineering organization

  • Reach for automation first, you’d rather build a scalable, systematic solution to a security problem than solve it manually a hundred times

  • Get excited when something new lands on your desk, be it an interesting vulnerability, a sweet exploit, a novel agentic architecture, an unfamiliar cloud primitive, or a bug class you haven’t seen before

  • 2+ years of industry experience designing, building, or securing complex applications and cloud systems

  • Hands-on experience with several of the following: security reviews, SDLC practices, secure CI/CD, architecture reviews, threat modeling, vulnerability management, bug bounty and responsible disclosure programs

  • Degree in Computer Science or a related field, equivalent training, or professional experience

  • A collaborative approach to problem solving paired with strong written and verbal communication

  • Experienced and comfortable programming in at least one language, and able to read and reason about code in Python, Typescript, Go, or Rust

  • Familiarity with using distributed cloud technology (AWS, GCP, Azure, Kubernetes, Docker, Terraform, etc.) and an understanding of how those technologies are secured (cloud networking, IAM, etc.)

  • Not sure if you meet 100% of the qualifications? We encourage you to apply anyway. We’re interested in people are excited about this opportunity and eager to grow