✦ Luna Orbit — Cybersecurity

Staff Product & Application Security Engineer

at Workiva

📍 Remote, US Remote 💰 $129K – $207K USD / year Posted April 01, 2026
Salary $129K – $207K USD / year
Type Full-Time
Experience lead
Exp. Years 6+ years
Education Bachelor’s degree or equivalent experience
Category Cybersecurity

Staff level security engineering role focusing on product and application security across Workiva’s cloud platforms, including secure coding, threat modeling, and large-scale security initiatives.

  • Serves as technical security lead for large initiatives
  • Lead secure design and threat modeling
  • Define security standards and patterns
  • Develop metrics for security program maturity
  • Coach senior engineers

Hands-on security with Java/JS/TypeScript/Python, cloud security across AWS/GCP/Azure, threat modeling, secure code reviews, and DevSecOps tooling (Semgrep, GH Security, Trivy, Grype).

The ideal candidate is a senior security engineer with breadth in application security, cloud security (AWS/GCP/Azure), secure coding, and threat modeling, capable of leading large security initiatives and mentoring engineers.

6+ years of related experience with a Bachelor’s degree or equivalent experience3+ years of software development experience in JavaJavaScript/TypeScriptPythonor GoDeep knowledge of application security secure coding practicesthreat modelingand OWASP Top 10Experience leading secure code reviewsarchitecture reviewsand security design discussionsAbility to communicate complex security concepts to technical and executive stakeholdersExperience using Burp SuiteStrong understanding of cloud security conceptsparticularly in AWS environmentsHands-on penetration testing experience across modern web applicationsFamiliarity with DevSecOps tooling such as SemgrepGitHub Advanced SecurityTrivyGrypeProven experience driving large-scale security initiatives (e.g.Zero Trustsecret management)
Advanced web application penetration testing certifications (OSWA OSWE OSCP BSCP eWTP GWAPT)Secure code review or application security certifications (CASE Java or OSWE)Cloud security certifications (AWS Security - Specialty or Google Cloud Professional Cloud Security Engineer)WAF tuning and optimizationExperience securing or evaluating AI-driven systemsExpertise across multiple cloud providers (AWSGCPAzure)
Burp SuiteSemgrepGitHub Advanced SecurityTrivyGrypeAWSGoogle Cloud PlatformAzureWeb Application Firewall (WAF)
['6+ years of related experience''Java''JavaScript/TypeScript''Python''Burp Suite''OWASP Top 10''Threat modeling''Secure code reviews''Architecture reviews''Security design discussions''DevSecOps''Semgrep''GitHub Advanced Security''Trivy''Grype''AWS''Amazon Web Services''Google Cloud Platform''Azure''Web Application Firewall (WAF)''Zero Trust''Secrets management''Authentication services''Production security services/systems']
JavaJavaScript/TypeScriptPythonBurp SuiteOWASP Top 10Threat modelingSecure code reviewsArchitecture reviewsSecurity design discussionsDevSecOpsSemgrepGitHub Advanced SecurityTrivyGrypeAWSAmazon Web ServicesGoogle Cloud PlatformAzureWeb Application Firewall (WAF)Zero TrustSecrets managementAuthentication servicesProduction security services/systems
Strategic thinkingCommunication with executive stakeholdersLeadershipMentoringCross-functional collaborationProblem-solvingDecision making

Preferred

OSWAOSWEOSCPBSCPeWTPGWAPTCASE JavaOSWEAWS Certified Security - SpecialtyGoogle Cloud Professional Cloud Security Engineer
Industry SaaS
Job Function Technical security leadership for product and cloud security initiatives
Role Subtype Staff Security Engineer
Tech Domains Amazon Web Services, Google Cloud Platform, Azure, Java, JavaScript, Python, REST/SOAP APIs, Kubernetes, Docker, GitHub
staff product & application security engineerapplication securitysecure coding practicesthreat modelingOWASP Top 10Burp SuiteSecure code reviewsarchitecture reviewssecurity design discussionsDevSecOpsSemgrepGitHub Advanced SecurityTrivyGrypeAWSAmazon Web ServicesGoogle Cloud PlatformAzureWeb Application FirewallZero TrustSecrets managementAuthentication servicesProduction security services10+ engineering teams

Must have strong hands-on security and development background, Experience with cloud providers (AWS, GCP, Azure)

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile