AlphaSense Oy logo
Monthly
€11,357 - €15,626
Posted August 7, 2026 · 21 days agoLast seen August 27, 2026Est. expiry September 11, 2026

Application Security Engineer

Senior Application Security Engineer
How this salary compares
Salary Context: Application Security Engineer

Hover or tap a row for full statistics (EUR / month on this chart).

Salary analysis

Compared with the selected benchmark ("All roles in Remote - United States"), this listing's salary midpoint is about 4% lower. The offer still falls within the benchmark range (€6,945–€25,355). The listed pay band (€13,083–€18,000) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 10 comparable listings.

Monthly salary comparison for Application Security Engineer
MarketLower bound (25th percentile)MedianUpper bound (75th percentile)
All roles in Remote - United States€6,945/per month€11,801/per month€25,355/per month
About the role

AlphaSense is investing in the next generation of our Application Security capability, a continuous, AI-augmented, layered defense program built for a SaaS engineering organization where AI agents and human developers ship code side by side at high velocity. As a Senior AI Application Security Engineer, you will be a senior individual contributor at the center of that program. You will own the code and pull-request enforcement layer that every change flows through, whether authored by a human or an AI coding agent. You will define and harden the deterministic security gates that make AI-authored code auditably equivalent to human-authored code, and partner directly with engineering teams shipping AI-native and agentic features, including MCP integrations, AI coding assistants, and AI capabilities embedded in our research workflows, so those features are designed, built, and operated securely from the start. This is a hands-on, build-it role. Not an auditor. Not a dashboard owner. We are looking for a security engineer who writes code, reads pull requests fluently across multiple languages, has personally shipped or integrated with agentic and MCP systems, and treats Application Security as a partnership with engineering rather than a gate to enforce. You will report to the Director of Application Security within Product Security, and partner closely with our broader Security, Engineering, and GRC teams. This is a foundational hire with a clear path to Staff / Tech Lead as the team grows. What You'll Own Continuous Code & PR Security (primary ownership) - Operate and continuously tune the SAST, SCA, secrets-detection, and SBOM pipeline. - Design, ship, and harden the deterministic security gates that make AI-authored PRs auditably equivalent to human-authored ones. - Review human-authored and agent-authored PRs, catching the semantic violations static analysis misses. Co-submit AI-generated patch proposals so human effort scales as review-and-merge, not authorship. - Drive findings to closure at the class level, fix a token-handling bug once at the platform layer and watch it propagate. Agentic & AI Security - Own how we secure AI-assisted development: Claude Code, Cursor, Copilot, MCP servers, agent-authored PRs, sub-agents handling rebases and CI fixes. - Author and roll out our AI-Assisted Development Security policy: prompt injection defense, MCP scope and credential governance, agent credential inheritance, secret leakage to agent logs, agent-action audit attribution. - Partner with harness engineering on agent scope declarations, agent identity registration, and the verification hooks that distinguish agent-initiated actions from human-initiated ones in the audit stream. - Threat model new AI features , agent gateway, MCP connector architecture, AI workflows in the research platform , and ship the controls. Threat Modeling & Developer Enablement - Scale the threat modeling framework. Pilot with the highest-risk teams, then make it standard for new features and architectural changes. - Partner with the product security team to build a security training program engineers actually use: secure coding patterns, authentication and authorization fundamentals, prompt injection awareness, how to engage Product Security on a design. - Embed testable security acceptance criteria, agent scope declarations, and verification hooks into the PRD template so services declare their security posture at design time. Layered Security - Continuous Security Testing is a five-layer model: Code (yours), Infrastructure & Contract, Behavioral Intelligence, Adversarial Simulation, and Data Segmentation. You won't operate all five, but you'll integrate tightly with the teams that do and ensure your Layer 1 signal is consumable by Layers 2-5 and by GRC for compliance evidence. Detection-to-Response Velocity - Drive MTTR on critical findings under 24 hours, finding precision above 95%, and recurring named classes trending to zero quarter over quarter. - Support DAST deployment, the API pen test program, and the customer-facing security posture dashboard. - Coordinate penetration testing, bug bounty intake, and partner threat-intel feeds , translating external attack-pattern disclosures into detections within days, not quarters. - Act as the primary technical responder for application-layer incidents, agentic behavior anomalies, or third-party integration compromises; leading the forensic investigation, architectural containment, and post-incident hardening requirements. What You Bring Required - 6+ years engineering experience, with 4+ in a dedicated AI Application Security / Product Security role at a SaaS or cloud-native company. Not a consulting / audit background. - Development background , hands-on and recent. You write code, not just review it. You can read PRs fluently in at least two of Python, TypeScript / JavaScript, Java / Kotlin, or Go, and you are comfortable in Terraform, Helm, and Kubernetes manifests. - Hands-on experience with agentic AI and MCP development. You have personally built with, integrated, or operated agentic tooling. Examples that qualify: built an MCP server; integrated Claude Code, Cursor, or Copilot into a real engineering workflow under governance; worked with autonomous coding agents or harnesses; built or hardened an agent gateway; shipped guardrails for prompt injection, jailbreak resistance, or output sanitization in production. - Production operation of a SAST / SCA pipeline at scale , Snyk, Semgrep, GitHub Advanced Security, Checkmarx, Veracode, or equivalent , including rule authoring, false-positive tuning, and CI/CD integration. - Demonstrated ownership of a threat modeling or developer security training program , founder or substantial contributor. You can describe the artifacts, the integration into the design process, and the metrics that proved it worked. - Layered security thinking. Defense-in-depth across code, contract, behavior, simulation, and data. You can speak to how findings at one layer propagate to others, and how to design for compounding control rather than redundant control. - Strong written communication. You author policy, guidance, runbooks, and PR comments that engineers read and act on. Nice to Have - Open-source contributions to a SAST / SCA tool, a security linter, an MCP server or framework, an agent harness, or a threat modeling tool. - Experience shipping a deterministic compliance gate that an external auditor accepted as equivalent to human review. - API security and DAST experience (Burp Suite, ZAP, Akto) and modern container / Kubernetes security (admission controllers, runtime protection, supply chain attestation). - AWS security depth (IAM, KMS, GuardDuty, Security Hub, Organizations) and exposure to AI/ML production environments. - Security partner on a customer-facing posture dashboard or DDQ response process, ideally in a regulated industry. - Public writing or speaking on developer security, AI/agent security, or AppSec automation. - Pre-IPO experience or familiarity with SOC 2 Type II, ISO 27001:2022, ISO 42001, SOX, GDPR. - Certifications: OSWE, OSCP, CSSLP, AWS Security Specialty, or CISSP.

Job Details

Responsibilities

  • Operate and tune SAST, SCA, secrets-detection, and SBOM pipelines
  • Design and harden deterministic security gates for AI-authored pull requests
  • Review human and agent-authored PRs for semantic violations
  • Secure AI-assisted development tools including Claude Code, Cursor, Copilot, and MCP servers
  • Author and implement AI-Assisted Development Security policies (prompt injection, credential governance)
  • Scale the threat modeling framework and build security training programs for engineers
  • Integrate security acceptance criteria into PRD templates
  • Act as primary technical responder for application-layer incidents and agentic behavior anomalies
  • Coordinate penetration testing and bug bounty intake

Requirements

  • 6+ years engineering experience, with 4+ in a dedicated AI Application Security / Product Security role at a SaaS or cloud-native company
  • Recent hands-on development background; fluent in at least two of Python, TypeScript/JavaScript, Java/Kotlin, or Go
  • Comfortable with Terraform, Helm, and Kubernetes manifests
  • Hands-on experience with agentic AI and MCP development (e.g., built MCP server, integrated Claude Code/Cursor/Copilot)
  • Experience operating SAST/SCA pipelines at scale (e.g., Snyk, Semgrep, GitHub Advanced Security)
  • Demonstrated ownership of a threat modeling or developer security training program
  • Strong written communication skills for authoring policies and guidance

Skills & Technologies

PythonTypeScriptJavaScriptJavaKotlinGoTerraformHelmKubernetesSASTSCASnykSemgrepGitHub Advanced SecurityCheckmarxVeracodeMCP (Model Context Protocol)Claude CodeCursorCopilotAWSIAMKMSGuardDutySecurity Hub
Seen 1 day agoPartial Schema
Financial overview
€28.2M
Revenue
€14.9M
Profit
53.0%
Profit margin
AlphaSense Oy logo
AlphaSenseOy · 216 open roles
Top locations: Remote - Global · 176 · Helsinki, Finland · 27 · Singapore · 2+9 other locations
View company
Current open roles at AlphaSense Oy on JobCrawls
LocationActive listings
Remote - Global176
Helsinki, Finland27
Singapore2
London, UK2
New York, USA2
New York City, United States1
Remote - Finland1
London, United Kingdom1
Remote1
New York, United States1
Remote - Europe1
Bangalore, India1
Current role mix at AlphaSense Oy on JobCrawls
Role typeActive listings
Software Engineer28
Account Manager9
Product Manager6
Customer Success Manager6
Channel and Customer Research Associate5
Compliance Analyst5
Account Executive4
Content Analyst4
Sales Development Representative4
Product Designer4
Principal Software Engineer3
Human Resources Specialist3
Network Engineer3
Analyst3
AI Platform Engineer3
Analyst Development Representative3
Android Engineer3
Customer Support Specialist2
Operations Manager2
People Business Partner2
Head of Developer Experience2
Data Scientist2
Enterprise Account Executive2
IT Support Analyst2
Pre-Sales Manager2
Sector Lead2
Program Manager2
Technical Program Manager2
Site Reliability Engineer2
Customer & Product Support Analyst2
iOS Engineer2
Design Engineer2
Sales Development Manager2
Senior Manager2
Associate Account Executive2
Manager2
Principal Design Engineer2
Cloud Platform Engineer2
Customer Education Manager1
Staff Engineer1
Equity Research1
Channel and Customer Research Sector Lead1
Revenue Accounting1
Senior Technical Program Manager1
Revenue Tools Specialist1
Payroll Director1
Product Security1
Account Director1
Tax Associate1
Head of Strategic Alliances1
Team Leader1
Director of Executive Recruiting1
Customer Support Analyst1
Strategic Account Leader1
Deal Desk Contracting Manager1
Business Applications Security Engineer1
Key Account Director1
Sales Operations Analyst1
Marketing AI & Transformation Strategy Lead1
Product Analyst1
Head of Broker Relations1
Senior Software Engineer1
Content Support Analyst1
Analytics Engineer1
Executive Assistant1
Financial Data Application Specialist1
Solutions Marketing Manager1
Implementation Consultant1
Human Resources1
Director of Global Real Estate and Workplace Experience1
Marketing Manager1
Program Management1
Senior Staff Software Engineer1
Legal Content and Data Director1
Product Platforms Engineer1
Embedded Client Platform Engineer1
Pre-Sales Consultant1
Motion Designer1
Deal Desk Analyst1
Analyst Development1
Business Applications Security1
Equity Research Associate1
Security Operations Analyst1
Compliance Surveillance Analyst1
Strategic Account Executive1
Audio Visual Engineer1
Strategic Sales Manager1
Strategic Finance Manager1
Senior Engineer1
Senior Commercial Counsel1
Researcher1
Account Management1
People Operations Coordinator1
Solutions Consultant1
Director of AI Governance and Security1
Data Analyst1
Core Developer Experience Engineer1
Revenue Operations Manager1
Marketing Analyst1
Sales Enablement1
Current role-level mix at AlphaSense Oy on JobCrawls
Role levelActive listings
Mid-Level162
Senior12
Manager3
Executive1

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.