Security Engineer, Application
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
The Application Security Lead will build and scale Serval’s product and application security program.
The role covers secure software development, vulnerability management, threat modeling, and security architecture across the platform and agentic systems.
The position combines hands-on technical leadership, team building, and close partnership with Engineering and Product.
Key Skills for This Role
Full Job Posting
Who we are
Serval is an AI-native automation platform that builds intelligent agents for high-volume operational workflows.
Its platform is used across business functions including IT, HR, Finance, Security, Legal, and Engineering.
Role overview
The Application Security Lead will build and scale Serval’s product and application security program.
The role covers secure software development, vulnerability management, threat modeling, and security architecture across the platform and agentic systems.
The position combines hands-on technical leadership, team building, and close partnership with Engineering and Product.
What you’ll do
- Design and operate application security practices across services, the agent platform, integrations, and customer-facing surfaces.
- Build and mentor teams covering product security, secure software development, and vulnerability management.
- Establish secure coding standards, reusable security frameworks, and scalable security design patterns.
- Build and tune SAST, DAST, SCA, secrets scanning, supply-chain controls, and CI/CD security gates.
- Own vulnerability intake, triage, severity assessment, remediation SLAs, tracking, and coordinated disclosure.
- Embed authentication, authorization, tenant isolation, data protection, and secrets management into platform systems.
- Address prompt injection, unsafe tool use, data exfiltration, and autonomous-action abuse in agentic AI workflows.
What you’ll need
- 10+ years of cybersecurity experience with deep expertise in application security, secure software development, and vulnerability management.
- Experience building and leading application or product security, secure-SDLC, and vulnerability-management functions.
- Strong software engineering fundamentals and the ability to read, write, and review production code.
- Deep expertise in modern application security tooling, software supply-chain security, and cloud-native distributed-systems architecture.
- Understanding of adversary tradecraft and application-layer exploitation, with experience applying it to secure design and remediation.
- Exceptional communication, leadership, influence, integrity, and ability to drive durable improvements across teams.
- Interest in AI-agent security challenges is a bonus.
What we offer
- Serval offers the opportunity to shape product and company security, grow with a new AI product, and work in a culture valuing innovation, ownership, accountability, and fun.
About serval
Serval is a private AI-native ITSM company automating help desks, access, and workflows for enterprise teams.
Visit company websiteApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at serval
Data Engineer
San Francisco, USA
Serval is seeking a senior Data Engineer to become its first dedicated data hire and own the data stack end to end. The role covers warehouses, pipelines, modeling, data quality, governance, self-serve analytics, and sta
Security Engineer, Corporate
San Francisco, USA
Serval is seeking a hands-on Corporate Security leader to secure its workforce, devices, SaaS estate, identity systems, and corporate network. The role requires 10+ years of cybersecurity experience, deep macOS endpoint
Security Engineer, Infrastructure
San Francisco, USA
Serval is seeking an Infrastructure Security Lead to secure AWS, Kubernetes, container, networking, and CI/CD infrastructure. The role combines hands-on technical leadership with team building, cloud and identity securit