Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Application Security Engineer image - Rise Careers
Job details

Senior Application Security Engineer

This is a hybrid role based in our Chicago or Bay Area Offices (San Francisco or Palo Alto) and will require you to be in the office on Tuesdays and Thursdays.

What’s so interesting about this role?

As a Staff Application Security Engineer at Grindr, you will be a key player in securing our platform, protecting millions of users, and ensuring best-in-class security practices. This role will elevate our application security strategy, leading efforts across web, mobile, and API security, while partnering with engineering teams to embed security into our development lifecycle.

You will architect and implement security tooling, drive DevSecOps initiatives, and act as a trusted advisor for application security across the organization. This is an opportunity to take Grindr’s security posture to the next level in a high-impact role.

What’s the job?

  • Assess & Improve Security Posture – Partner with engineering teams to evaluate the security state of our applications (web, mobile, APIs), identify risks, prioritize security efforts, and drive remediation.

  • Build & Deploy Security Tooling – Architect and manage security solutions, including SAST, DAST, and Fuzzing tools, integrating them seamlessly into our DevSecOps pipelines.

  • Lead Secure SDLC Initiatives – Collaborate with developers to integrate security into CI/CD workflows, ensuring security is a core component of Grindr’s software development process.

  • Security Culture & Stakeholder Collaboration – Work cross-functionally with product, engineering, compliance, and executive teams to ensure security is prioritized and embedded into the company’s DNA.

  • Third-Party & Bug Bounty Programs – Manage security engagements with third-party organizations and oversee Grindr’s bug bounty program to identify and address vulnerabilities proactively.

  • Incident Response & Threat Modeling – Contribute to security incident response, forensics, and threat modeling efforts, ensuring proactive risk mitigation.

  • Mentor & Educate – Provide security guidance to engineers, conduct training sessions, and advocate for secure coding practices.

What we’ll love about you

  • 8+ years of experience in Application Security, Software Security, or DevSecOps, with a focus on securing web, mobile, and cloud applications.

  • Proficiency in security tooling – hands-on experience with SAST/DAST tools (e.g., SonarQube, Snyk, GitHub Advanced Security, BurpSuite, FFUF).

  • Deep expertise in secure software development – Strong knowledge of OWASP Top 10, secure coding practices, and ability to conduct code reviews to identify security flaws.

  • Cloud & Infrastructure Security – Experience securing cloud environments (AWS, GCP) and working with containerized architectures (Docker, Kubernetes) or similar

  • Strong leadership & communication skills – Ability to lead security initiatives, influence engineering teams, and communicate security risks effectively to technical and non-technical stakeholders.

  • Experience with regulatory frameworks – Familiarity with SOX, GDPR, PCI, and SOC compliance and ability to ensure applications meet security and regulatory standards.   

We’ll really swoon if you are/have

  • Experience leading bug bounty programs and working with external security researchers.

  • Hands-on development experience in web and mobile technologies (e.g., Node.js, JavaScript, Swift, Kotlin).

  • Familiarity with threat modeling frameworks and experience designing secure architectures for large-scale applications.

  • Knowledge of serverless and microservices security best practices.

What you'll love about us

  • Mission and Impact: Grindr is building the global gayborhood in your pocket. Your role will impact the lives of millions of LGBTQ+ people around the world. Through our success, we are making a world where the lives of our community are free, equal, and just.

  • Family Insurance: Insurance premium coverage for health, dental, and vision for you and partial coverage for your dependents.

  • Retirement Savings: Generous 401K plan with 6% match and immediate vest in the U.S.

  • Compensation: Industry-competitive compensation and eligibility for company bonus and equity programs.

  • Queer-Inclusive Benefits: Industry-leading gender-affirming offerings with up to 90% cost coverage, access to Included Health, monthly stipends for HRT, and more.

  • Additional Benefits: Flexible vacation policy, monthly stipends for cell phone, internet, wellness, food, and commuting, breakfast/lunch provided onsite, and yearly travel & leisure stipend.

About Grindr

Grindr is building the global gayborhood in your pocket. With more than 13.5 million monthly active users, Grindr has become a fundamental part of the LGBTQ+ community and is charting a path to make the world more free, equal, and just. Since 2015, Grindr for Equality has advanced safety, health, and human rights for millions of Grindr users and the global LGBTQ+ community in partnership with more than 100 community organizations in every region of the world.

Our next evolution is underway as a public company that continues to grow and build meaningful experiences for our users. From social issues to product innovations, we're setting audacious goals for our community and the business, and leveraging the latest tech stacks and a culture of engineering excellence to make it happen. At the heart of our work in this new chapter is a shared set of operating principles centered around cultivating curiosity, thinking big, setting and expediting our ambitious goals, and growing through iteration; all while keeping our users #1.

Grindr is headquartered in West Hollywood, California, with offices in the Bay Area, Chicago, and New York. With a track record of strong financial performance and plans for continued headcount growth, we’re building a team of talented, passionate, and open-minded people who want to disrupt the dating app space, innovate products, and advance LGBTQ+ culture. Come be a part of this exciting journey with us.

Grindr is an equal-opportunity employer

To learn more about how we handle the personal data of applicants, visit our Employee and Candidate Privacy Policy.

 

#LI-Hybrid

Grindr Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Grindr DE&I Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Grindr
Grindr CEO photo
Jeff Bonforte
Approve of CEO

Average salary estimate

$140000 / YEARLY (est.)
min
max
$120000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Application Security Engineer, Grindr

Are you ready to take your application security expertise to the next level? Join Grindr as a Senior Application Security Engineer, where you’ll play a vital role in securing our platform and protecting millions of users. Based in Chicago or the Bay Area, this hybrid position is all about collaboration and innovation. You’ll assess the security posture of our web, mobile, and API applications, partnering closely with engineering teams to prioritize and remediate risks. Your responsibility extends to architecting and implementing robust security tooling, driving our DevSecOps initiatives, and fostering a culture of security across the organization. With your extensive experience in application security, you'll lead secure SDLC initiatives, ensuring that security becomes a core component of our development lifecycle. Plus, you’ll have the chance to manage third-party and bug bounty programs, contributing to our proactive stance on vulnerabilities. This role offers the opportunity to mentor engineers and educate the team on secure coding practices, while also being a key advisor on security measures. If you have a deep understanding of SAST/DAST tools and experience in cloud security, your skills are just what we need. At Grindr, you'll not only impact the security of our application but also have the chance to shape the future of a platform that matters to millions in the LGBTQ+ community.

Frequently Asked Questions (FAQs) for Senior Application Security Engineer Role at Grindr
What responsibilities does the Senior Application Security Engineer have at Grindr?

The Senior Application Security Engineer at Grindr is responsible for enhancing the security posture of our platform across web, mobile, and API applications. This includes assessing application security, managing security tools, leading secure SDLC initiatives, collaborating cross-functionally, and overseeing third-party and bug bounty programs to proactively identify vulnerabilities.

Join Rise to see the full answer
What qualifications are necessary for the Senior Application Security Engineer position at Grindr?

To qualify for the Senior Application Security Engineer role at Grindr, candidates should have 8+ years of experience in application security or related fields, a strong understanding of SAST/DAST tools, experience in cloud security (AWS, GCP), and familiarity with secure software development practices and regulatory frameworks such as SOX and GDPR.

Join Rise to see the full answer
How does the Senior Application Security Engineer contribute to Grindr's mission?

The Senior Application Security Engineer at Grindr not only secures our applications but also contributes to the larger mission of supporting the LGBTQ+ community by ensuring the safety and integrity of the platform that millions rely on. By embedding security practices into our development process, you help create a safe environment for users to connect.

Join Rise to see the full answer
What types of security tools will the Senior Application Security Engineer use at Grindr?

At Grindr, the Senior Application Security Engineer will utilize a variety of security tools, including SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), and fuzzing tools to ensure applications are secure throughout the development lifecycle and to integrate these tools into our DevSecOps pipelines.

Join Rise to see the full answer
What is the significance of the bug bounty program that the Senior Application Security Engineer manages at Grindr?

The bug bounty program managed by the Senior Application Security Engineer at Grindr is crucial for proactively identifying and addressing vulnerabilities in our applications. By engaging external security researchers, we leverage their expertise to strengthen our security posture and continuously improve our platform's safety.

Join Rise to see the full answer
Common Interview Questions for Senior Application Security Engineer
Can you explain your experience with security tooling like SAST and DAST for the Senior Application Security Engineer role?

When answering this question, focus on specific tools you’ve used, such as SonarQube or BurpSuite. Highlight how you've integrated these tools into CI/CD pipelines and share any metrics or results from previous implementations that improved application security.

Join Rise to see the full answer
What do you consider the top security risks when securing web and mobile applications?

Outline your knowledge of risks like OWASP Top 10 vulnerabilities. Discuss how you would prioritize risks based on the application context, user data sensitivity, and potential impact, demonstrating your analytical thinking in assessing risks and recommending mitigations.

Join Rise to see the full answer
How do you approach integrating security into the software development lifecycle?

Describe a systematic approach where security checks are integrated at every stage of development, from planning through deployment. Emphasize collaboration with development teams to ensure security is a shared responsibility, promoting secure coding practices and regular training.

Join Rise to see the full answer
Describe a challenging incident response situation you managed.

Share a specific incident where you led the response team, what the incident was, the steps you took, and the lessons learned. Highlight your ability to communicate effectively with various stakeholders and adapt your strategies under pressure.

Join Rise to see the full answer
How do you mentor and educate engineering teams on secure coding practices?

Discuss your approach to training sessions, workshops, or creating documentation. Provide examples of how you’ve effectively communicated complex security concepts to non-technical stakeholders, ensuring that the principles of secure coding become second nature to the team.

Join Rise to see the full answer
What best practices do you follow when conducting threat modeling?

Outline a structured method you apply, such as identifying assets, potential threats, and vulnerabilities. Explain how you prioritize these threats based on likelihood and impact, and how this process aids in reinforcing security measures during development.

Join Rise to see the full answer
How do you measure the effectiveness of security initiatives you implement?

Talk about key metrics you track, such as reduction in vulnerabilities, time taken for remediation, and feedback from stakeholders. Mention using both quantitative data and qualitative assessments to gauge improvements in security and team awareness.

Join Rise to see the full answer
In your opinion, what is the importance of a bug bounty program?

Emphasize the role of a bug bounty program in identifying vulnerabilities from diverse sources. Discuss how it complements your in-house security assessments and engages external expertise to enhance the overall security posture.

Join Rise to see the full answer
Can you provide an example of how you’ve collaborated across departments to enhance security?

Describe a situation where you collaborated with product, engineering, or compliance teams to address a security concern or integrate new security measures, showcasing your ability to communicate and work effectively with various stakeholders.

Join Rise to see the full answer
What motivates you to work in application security, specifically at Grindr?

Articulate your passion for technology and security while connecting it to Grindr's mission. Highlight your interest in making a positive impact in the LGBTQ+ community and how this aligns with your professional goals in application security.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Grindr Remote No location specified
Posted 6 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Family Medical Leave
Paid Holidays
Photo of the Rise User
Grindr Remote No location specified
Posted 6 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Family Medical Leave
Paid Holidays
Photo of the Rise User
AECOM Remote Sydney, NSW, Australia
Posted 6 days ago
Photo of the Rise User
Anduril Industries Hybrid Costa Mesa, California, United States
Posted 5 days ago
Dynamic Group Inc Hybrid Ramsey, Minnesota, United States
Posted 2 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 3 days ago
Passion for Exploration
Dare to be Different
Customer-Centric
Diversity of Opinions
Inclusive & Diverse
Photo of the Rise User
Posted 3 days ago

Connect queer people with one another and the world.

55 jobs
MATCH
VIEW MATCH
BADGES
Badge LGBTQ+ LedBadge Future Maker
BENEFITS & PERKS
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Family Medical Leave
Paid Holidays
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 27, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
C
Someone from OH, Port Clinton just viewed Data Entry Clerk at Comforce Resource
Photo of the Rise User
Someone from OH, Mason just viewed HR/Recruiting Assistant at Illumination
Photo of the Rise User
Someone from OH, Strongsville just viewed Used Car Buyer - Concord Toyota at Sonic Automotive
Photo of the Rise User
Someone from OH, Cincinnati just viewed Mid-level Creative (f/m/d) at Landor
Photo of the Rise User
70 people applied to Electrical Apprentice at Aerotek
P
Someone from OH, Kent just viewed Graphic Designer at ProjectGrowth
Photo of the Rise User
Someone from OH, Waverly just viewed Client Services Manager at Pepperstone
Photo of the Rise User
Someone from OH, Plain City just viewed Aesthetic Telehealth Nurse Practitioner (remote) at Moxie
Photo of the Rise User
Someone from OH, Columbus just viewed EdTech Product/Program Manager at Planner5D
S
Someone from OH, Lorain just viewed Test Engineer- Ninja at SharkNinja
Photo of the Rise User
Someone from OH, Youngstown just viewed Channel Development Representative at Arrow Electronics
Photo of the Rise User
Someone from OH, Cincinnati just viewed Buyer at Novolex
k
Someone from OH, Columbus just viewed Patient Experience Coordinator at knownwell
Photo of the Rise User
Someone from OH, Columbus just viewed Store Manager - New Store Opening at Curaleaf
Photo of the Rise User
Someone from OH, Akron just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Norwalk just viewed Hybrid Account Manager-Commercial Lines at AssuredPartners
Photo of the Rise User
Someone from OH, Loveland just viewed Animator at Apex Systems Bellevue, WA at Apex Systems
Photo of the Rise User
Someone from OH, Canton just viewed Lead Jr. Toddler Teacher at All Around Children
Photo of the Rise User
Someone from OH, Mentor just viewed Site Merchandising Manager at Lovepop
Photo of the Rise User
Someone from OH, Batavia just viewed Restaurant Busser at Outback Steakhouse