Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Staff Security Engineer, AppSec image - Rise Careers
Job details

Staff Security Engineer, AppSec

About Kandji


Kandji is the Apple device management and security platform that empowers secure and productive global work. With Kandji, Apple devices transform themselves into enterprise-ready endpoints, with all the right apps, settings, and security systems in place. Through advanced automation and thoughtful experiences, we’re bringing much-needed harmony to the way IT, InfoSec, and Apple device users work today and tomorrow.


Some of the smartest money in tech has partnered with Kandji to realize our vision, including Tiger Global, Felicis, Greycroft, First Round Capital, and Okta Ventures. In July 2024, Kandji raised $100 million in capital from General Catalyst, bringing Kandji’s valuation to $850 Million.


Since Kandji’s Series C in 2021, the company has seen a 600%+ increase in annual recurring revenue, and its customer base has grown nearly 4X across 40+ industries. Notable customers include Allbirds, Canva, and Notion, and the company has partnerships with such industry giants as ServiceNow, AWS, and Okta.


Kandji was also named to Forbes’ Next Billion Dollar Startup List 2023 and recognized as a top venture-backed startup with the potential to reach unicorn status.


The Opportunity


The Staff Security Engineer, AppSec will play a critical role in safeguarding Kandji’s products and infrastructure by designing security programs, conducting thorough threat modeling, managing vulnerabilities, and embedding secure development practices. This role will work closely with product managers, engineering teams, and cross-functional stakeholders to ensure security is a foundational component of all our initiatives.


How You Will Make a Difference Day to Day:
  • Threat Modeling: Lead the development of comprehensive threat models for new and existing products to identify, assess, and mitigate security risks.
  • Vulnerability Management: Establish and manage a vulnerability management lifecycle for our applications, ensuring timely detection, reporting, and remediation of security vulnerabilities.
  • Security Programs: Design and implement application security programs focused on building security into the software development lifecycle (SDLC) and establishing secure coding practices.
  • Collaboration with Engineering: Partner with product and engineering teams to integrate security requirements into architectural designs and development processes.
  • Security Audits & Assessments: Conduct regular security assessments of applications and infrastructure, focusing on identifying areas of weakness and recommending actionable improvements.
  • Security Incident Response: Support the incident response team in application-related security incidents by providing expertise on containment, eradication, and post-incident analysis.
  • Security Awareness: Mentor and coach engineering teams on security best practices and create security awareness initiatives tailored to the development environment.
  • Automation & Tooling: Drive the adoption of security automation, including code scanning, security testing, and CI/CD pipeline integration to streamline security processes.


Minimum Qualifications:
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field, or equivalent experience.
  • 8+ years of experience in application security, preferably within a SaaS environment.
  • Strong proficiency in threat modeling, secure coding practices, vulnerability management, and incident response.
  • Hands-on experience with security tools such as static/dynamic analysis tools (SAST, DAST), penetration testing tools, and CI/CD pipeline integration.
  • Familiarity with modern programming languages (e.g., Python, JavaScript, Go) and cloud platforms (e.g., AWS, GCP, Azure).
  • Industry certifications such as CISSP, OSCP, or CEH are a plus.
  • Required to work on-site 5x a week in our Miami office (Coral Gables).


Minimum Qualifications:
  • Technical Leadership: Demonstrated ability to lead and guide teams in the development and execution of security initiatives.
  • Threat Analysis: Strong understanding of threat modeling techniques, application security risks (OWASP Top Ten), and secure coding practices.
  • Risk Management: Expertise in managing security vulnerabilities and threats through identification, prioritization, and mitigation strategies.
  • Communication: Excellent communication skills to effectively collaborate with cross-functional teams, present complex security concepts, and advocate for secure design practices.
  • Innovation & Problem Solving: Creative thinker with the ability to develop novel security solutions in response to emerging threats and vulnerabilities.
  • Continuous Improvement: Strong commitment to staying up-to-date with evolving security standards and best practices, and a passion for continuous learning and improvement.


Benefits & Perks


 • Competitive salary

 • 100% individual and dependent medical + dental + vision coverage

 • 401(k) with a 4% company match

 • 20 days PTO

 • Kandji Wellness Week the first week in July

 • Equity for full-time employees

 • Up to 16 weeks of paid leave for new parents

 • Paid Family and Medical Leave

 • Modern Health - Mental Health Benefits - Individual and Dependents

• Fertility Benefits

 • Working Advantage Employee Discounts

 • Free onsite fitness center

 • Free parking

 • Lunch 5 days/week

 • Exciting opportunities for career growth

 • An outstanding, inclusive culture


We are excited to be serving a significant need for a fast-growing market, and are proud of the high-performing team we have brought together so far. If you’re someone who wants to engage in new, exciting projects that will challenge your skills in the best way possible, we would love to connect with you.


At Kandji we believe in fostering an inclusive environment in which employees feel encouraged to share their unique perspectives, leverage their strengths, and act authentically. We know that diverse teams are strong teams, and welcome those from all backgrounds and varying experiences.


Kandji is proud to be an equal opportunity employer committed to diversity and inclusion in the workplace. Qualified applicants will be considered for employment without regard to race, color, religion, national origin, age, sex, sexual orientation, gender identity, physical or mental disability, protected veteran or military status or any other status protected by applicable law.

Kandji Glassdoor Company Review
3.4 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Kandji DE&I Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Kandji
Kandji CEO photo
Adam Pettit
Approve of CEO

Average salary estimate

$145000 / YEARLY (est.)
min
max
$130000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Staff Security Engineer, AppSec, Kandji

Kandji is on the lookout for a dedicated Staff Security Engineer, AppSec to join our vibrant team in Miami! As the leading Apple device management and security platform, we are committed to empowering secure and productive workplaces globally. In this role, you will be pivotal in safeguarding our products and infrastructure by designing robust security programs, conducting thorough threat modeling, and managing vulnerabilities. Your day-to-day responsibilties will involve working closely with product managers and engineering teams to ensure security is integrated into every aspect of our initiatives. If you’re passionate about driving security best practices, you'll play a key role in mentoring our engineering teams, conducting security audits, and supporting incident response teams during application-related security incidents. Your expertise will help us establish a secure development lifecycle and drive the adoption of security automation tools. At Kandji, we pride ourselves on our culture of continuous improvement and innovation, so you will have plenty of opportunities to grow and challenge your skills in this exciting environment. With a competitive salary, comprehensive benefits, and an inclusive culture that values diverse perspectives, Kandji is the perfect place for you to make a difference in the tech space. If this sounds like your kind of challenge, we would love to welcome you aboard as we continue to expand our impact in the tech world!

Frequently Asked Questions (FAQs) for Staff Security Engineer, AppSec Role at Kandji
What are the responsibilities of a Staff Security Engineer, AppSec at Kandji?

The Staff Security Engineer, AppSec at Kandji is responsible for designing and implementing security programs, conducting threat modeling, managing vulnerabilities, and collaborating with product and engineering teams to ensure security is integrated into the software development lifecycle. This role also involves conducting security audits and assessments, supporting incident response teams, and mentoring engineering teams on security best practices.

Join Rise to see the full answer
What qualifications are needed for the Staff Security Engineer, AppSec position at Kandji?

To qualify for the Staff Security Engineer, AppSec role at Kandji, candidates should have a Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field, plus at least 8 years of experience in application security, ideally within a SaaS environment. Proficiency in threat modeling, secure coding practices, and familiarity with security tools is essential. Industry certifications such as CISSP, OSCP, or CEH are a plus.

Join Rise to see the full answer
What kind of work culture can I expect at Kandji as a Staff Security Engineer, AppSec?

At Kandji, you can expect an outstanding, inclusive culture that thrives on diversity and innovation. The company fosters an environment where employees are encouraged to share their unique perspectives and leverage their strengths. You'll be part of a high-performing team that values collaboration and continuously seeks new ways to improve security practices.

Join Rise to see the full answer
What are some of the tools used by the Staff Security Engineer, AppSec at Kandji?

The Staff Security Engineer, AppSec at Kandji will use a variety of security tools, including static and dynamic analysis tools (SAST, DAST), penetration testing tools, and CI/CD pipeline integrations to enhance the security of applications. Familiarity with modern programming languages, such as Python and JavaScript, as well as cloud platforms like AWS is also important.

Join Rise to see the full answer
What benefits can I expect as a Staff Security Engineer, AppSec at Kandji?

As a Staff Security Engineer, AppSec at Kandji, you can expect a competitive salary and a robust benefits package that includes 100% individual and dependent medical, dental, and vision coverage, a 401(k) with a company match, generous PTO, paid family leave, and wellness programs. Kandji also invests in your professional development and offers exciting opportunities for career growth.

Join Rise to see the full answer
Common Interview Questions for Staff Security Engineer, AppSec
How do you approach threat modeling in application security?

To effectively approach threat modeling, I begin by identifying assets and potential threats to the application. I utilize established frameworks like STRIDE to categorize threats and assess their impact. Collaborating with cross-functional teams, I then document and prioritize potential vulnerabilities, ensuring that we design mitigations that align with security best practices.

Join Rise to see the full answer
Can you explain your experience with vulnerability management?

In my previous roles, I have managed the full vulnerability lifecycle, which includes identifying vulnerabilities through automated tools, assessing their impact through risk analysis, and coordinating timely remediation efforts across development teams. I also prioritize vulnerabilities based on their severity and exploitability, ensuring a focused and systematic approach to risk mitigation.

Join Rise to see the full answer
What strategies do you employ for application security best practices?

I advocate for the integration of secure coding practices within the software development lifecycle. This includes conducting regular security training for developers, implementing security checks in CI/CD pipelines, and maintaining an open line of communication with engineering teams to foster a culture of security awareness. Additionally, I emphasize the importance of regular security audits and assessments.

Join Rise to see the full answer
How do you handle a security incident?

In the event of a security incident, my first step is to contain the incident to prevent further damage. Next, I assess the breach's scope and impact, followed by coordinating with the incident response team to eradicate the issue. After initial mitigation, I conduct a post-incident analysis to identify root causes and improve our security posture moving forward.

Join Rise to see the full answer
What is your experience with secure coding practices?

I have extensive experience establishing secure coding standards within development teams. I promote the use of frameworks that emphasize defense-in-depth and secure design principles. By conducting code reviews and utilizing tools for static and dynamic analysis, I ensure compliance with our security benchmarks and provide feedback to enhance coding practices.

Join Rise to see the full answer
Can you describe a time you improved a security process?

In one of my previous roles, I identified bottlenecks in our vulnerability management process, which resulted in delays in remediation. I initiated a revamp of our tracking and reporting system, integrating vulnerability scanning tools and automating reporting. This improved our response time significantly and ensured a proactive security approach, reducing risk across our applications.

Join Rise to see the full answer
What tools do you commonly use for security assessments?

For security assessments, I regularly use tools like OWASP ZAP and Burp Suite for dynamic testing, along with SAST tools like SonarQube and Veracode. These tools help in identifying vulnerabilities throughout the development lifecycle, allowing for early detection and mitigation of security risks before they reach production.

Join Rise to see the full answer
How do you stay current with emerging security threats?

I prioritize continuous learning by regularly participating in security webinars, attending industry conferences, and following reputable security blogs and forums. I also engage with professional networks and organizations that focus on sharing knowledge and experiences related to emerging threats and best practices in the cybersecurity landscape.

Join Rise to see the full answer
What is your approach to mentoring junior security team members?

My approach to mentoring involves providing hands-on guidance and fostering an environment of open communication. I create opportunities for knowledge sharing through workshops and collaborative projects, encouraging junior team members to voice questions and ideas. I focus on building their confidence in security practices and decision-making skills.

Join Rise to see the full answer
How do you advocate for security within engineering teams?

I advocate for security within engineering teams by fostering partnerships that emphasize the importance of security in the development process. I conduct regular training sessions, provide resources for secure coding, and actively engage in design discussions to ensure security is a priority. By sharing success stories of the impact of good security practices, I can drive a culture of security throughout the team.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays

Join Kandji as a Graphic Designer and play a pivotal role in defining and executing the company’s innovative brand strategy.

Photo of the Rise User
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays

Join Kandji as a Security Researcher focusing on behavioral detections to enhance their Endpoint Detection and Response solutions.

Photo of the Rise User
Posted 6 days ago

Join DMI as a Junior First Response Engineer and be part of a team delivering top-notch digital services and technology solutions.

Photo of the Rise User
NetApp Remote US, Hennepin County, MN; Minnesota, Edina, MN
Posted 9 days ago

NetApp is looking for a Cloud Partner Technical Lead to enhance and manage cloud partnerships, primarily focused on AWS solutions.

Photo of the Rise User

Join AbbVie as an Associate Director – Senior Salesforce Architect to lead the development of innovative Salesforce solutions in a hybrid work environment.

Redcare Pharmacy Remote Probsteigasse 12-18, Cologne, Germany
Posted 14 hours ago

Become a vital part of Redcare Pharmacy's IT Transformation team and drive impactful technology projects that align with our mission for better health.

Photo of the Rise User
Posted 17 hours ago

Sony Corporation of America is looking for a Principal, Security Data Architect to drive data architecture initiatives within their Corporate Information Security Division.

Kanadevia Inova Remote Einsteinova, 851 01 Bratislava-Petržalka, Slovakia
Posted 13 days ago

Join Kanadevia Inova as an IT Application Specialist and help us transform waste into value through technology and innovation.

Photo of the Rise User
American Express Remote New York, New York, United States
Posted 16 hours ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as the VP of Technology Workforce and lead the charge in transforming our global talent strategy.

Photo of the Rise User
Posted 7 days ago

Join Alphatec Spine, Inc. as an SAP Basis & Security Engineer to optimize SAP infrastructures and enhance security measures.

Drawing on decades of experience in Apple IT, we saw a dire need for a device management platform that could accommodate growing businesses and increasing regulatory demands. Existing solutions were either overly simplistic or mind-numbingly compl...

56 jobs
MATCH
VIEW MATCH
BENEFITS & PERKS
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 29, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
13 people applied to Cyber security analyst at Optimiza
H
Someone from OH, Akron just viewed Brand Marketing Manager at Huntington
R
Someone from OH, Hamilton just viewed Forklift Operator Warehouse at Ryder
Photo of the Rise User
Someone from OH, Cincinnati just viewed Ad Ops Specialist, Display at System1
Photo of the Rise User
Someone from OH, Cincinnati just viewed FQHC Billing & Collections Manager at OhioGuidestone
Photo of the Rise User
Someone from OH, Cleveland just viewed Enrollment Specialist- Remote at Adtalem Global Education
o
Someone from OH, Dayton just viewed Marketing and Communications Specialist at osu
Photo of the Rise User
Someone from OH, Columbus just viewed Construction Coordinator at Meijer
T
11 people applied to Intern-Tech at TDS Telecom
Photo of the Rise User
51 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, Steubenville just viewed Legal & Compliance Internship at Smiths Group
Photo of the Rise User
Someone from OH, Warren just viewed Senior Front-End Developer at Worldly
Photo of the Rise User
62 people applied to SOC Analyst I at Epsilon
S
14 people applied to SOC Intern at SHEIN
Photo of the Rise User
Someone from OH, Tiffin just viewed Game Operations Specialist at Genius Sports
u
Someone from OH, Loveland just viewed Customer Service Agent - Part Time at uhaul
Photo of the Rise User
Someone from OH, Cleveland just viewed HR Manager at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Mid Level, System Administrator - (ETS) at Delivery Hero
Photo of the Rise User
Someone from OH, Mason just viewed Inside Sales Co-Op at VEGA Americas
Photo of the Rise User
Someone from OH, Sandusky just viewed Director of IT at Kyo
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health