Security Engineer
Starburst
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
2+ years
Job Description
About the role
As a Security Engineer II, you'll help advance Starburst's Application Security program by building the automation and tooling that allows a small team to secure a large engineering organization. You'll take security problems and turn them into reliable, automated systems, using AI where it adds leverage. This is a hands-on engineering role: you'll write production code, integrate security checks into CI/CD pipelines, and build automation and guardrails the program depends on.
You don't need deep specialist expertise in vulnerability management or offensive security. What matters is a solid information security foundation, strong engineering skills, and the judgment to make sound security tradeoffs. This role offers room to grow your security depth and take on broader product security responsibilities over time.
You'll work closely with Engineering and Product.
As a Security Engineer at Starburst you will:
- Build automation and tooling for the Application Security program, turning manual, repetitive, or hard-to-scale security work into reliable automated systems, increasingly powered by AI.
- Integrate security into the development lifecycle, enabling automated security checks within CI/CD pipelines and building reusable guardrails and secure-by-default components.
- Support and extend our security stack (SAST, DAST, SCA, secrets scanning), connecting tools so findings reach the right engineering team quickly and helping developers interpret and remediate them.
- Apply AI to scale security work, prototyping and productionizing AI-assisted workflows for triage, analysis, and remediation.
- Support vulnerability management operations, helping detect, triage, and route newly disclosed vulnerabilities, and making that process faster and more consistent.
- Make sound security tradeoffs and help improve secure coding standards, documentation, and remediation playbooks.