Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Engineer, AppSec  image - Rise Careers
Job details

Engineer, AppSec

About Zapier

We're humans who simply think computers should do more work.

At Zapier, we’re not just making software—we’re building a platform to help millions of businesses globally scale with automation and AI. Our mission is to make automation work for everyone by delivering products that delight our customers. You’ll collaborate with brilliant people, use the latest tools, and leverage the flexibility of remote work. Your work will directly fuel our customers’ success, and as they grow, so will you.

Job Posted: April 3, 2025
Location: Americas (EST or CST working hours required)

Hi there!

We’re looking for an Application Security (AppSec) Engineer to join our Security team at Zapier. We’re on a mission to democratize automation, while ensuring the security and privacy of millions of users worldwide by protecting sensitive data and building trust through robust security measures.

This role combines hands-on software development for our core security services (60-70%) with security engineering responsibilities (30-40%). As a member of the AppSec team within the Security organization, you will:

  • Shape security practices across development teams. And empower them to build and ship secure products.

  • Own critical security services protecting sensitive data at scale.

About You

  • You have strong Python backend development expertise, and have experience building and maintaining production services.

  • You have hands-on experience with Redis and PostgreSQL, and proficiency with distributed systems and cloud platforms (AWS).

  • You have a strong understanding of cryptographic principles. You have knowledge of authentication mechanisms, authentication / authorization patterns, and secure key management practices.

  • You have experience with security architecture and threat modeling. You have strong written and verbal communication skills to deliver constructive feedback regarding security matters to engineers and product designers, and an ability to balance security requirements with operational or business needs.

  • You understand secure development lifecycle and secure coding practices. You have knowledge of common web / API vulnerabilities and mitigations (e.g. OWASP Top 10). You think about your job as not just identifying individual vulnerabilities but also finding effective ways to eliminate whole classes of them.

  • Collaboration is second nature to you, and you're known for your willingness to roll up your sleeves and work alongside colleagues to achieve common goals.

  • You're adaptable. You've been in fast-growing companies and know how to build, change, and adapt to the needs of a company as it grows.

Things You’ll Do

  • Security Services Development:

  • Develop core security infrastructure services focusing on key management, encryption, and authentication.

    1. Build robust distributed systems leveraging Redis, PostgreSQL, and AWS services.

    2. Maintain high code quality standards through comprehensive testing, monitoring, and documentation.

    3. Design and operate scalable processes and build paved-path tooling that enable our engineers to ship secure products.

  • Security Threat Identification: Partner with development teams to conduct design reviews and threat modeling sessions.

  • Vulnerability Management: Support our public bug bounty program and leverage application testing tools (SAST, SCA) to identify, triage, and drive remediation of vulnerabilities.

  • Collaborative Security Support: Work closely with various other Security teams and partner with engineering teams to provide general ad hoc security support and technical/operational guidance.

How to Apply

At Zapier, we believe that diverse perspectives and experiences make us better, which is why we have a non-standard application process designed to promote inclusion and equity. We're looking for the best fit for each of our roles, regardless of the type of companies in your background, so we encourage you to apply even if your skills and experiences don’t exactly match the job description. All we ask is that you answer a few in-depth questions in our application that would typically be asked at the start of an interview process. This helps speed things up by letting us get to know you and your skillset a bit better right out of the gate. Please be sure to answer each question; the resume and CV fields are optional.

Education is not a requirement for our roles; however, if you receive an offer, you will need to include your most recent educational experience as part of our background check process.

After you apply, you are going to hear back from us—even if we don’t see an immediate fit with our team. In fact, throughout the process, we strive to never go more than seven days without letting you know the status of your application. We know we’ll make mistakes from time to time, so if you ever have questions about where you stand or about the process, just ask your recruiter!

Zapier is an equal-opportunity employer and we're excited to work with talented and empathetic people of all identities. Zapier does not discriminate based on someone's identity in any aspect of hiring or employment as required by law and in line with our commitment to Diversity, Inclusion, Belonging and Equity. Our code of conduct provides a beacon for the kind of company we strive to be, and we celebrate our differences because those differences are what allow us to make a product that serves a global user base. Zapier will consider all qualified applicants, including those with criminal histories, consistent with applicable laws.

Zapier prioritizes the security of our customers' information and is dedicated to adhering to all applicable data privacy laws. You can review our privacy policy here.

Zapier is committed to inclusion. As part of this commitment, Zapier welcomes applications from individuals with disabilities and will work to provide reasonable accommodations. If reasonable accommodations are needed to participate in the job application or interview process, please contact jobs@zapier.com

Application Deadline:

The anticipated application window is 30 days from the date job is posted, unless the number of applicants requires it to close sooner or later, or if the position is filled.

Even though we’re an all-remote company, we still need to be thoughtful about where we have Zapiens working. Check out this resource for a list of countries where we currently cannot have Zapiens permanently working.

Zapier Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Zapier DE&I Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Zapier
Zapier CEO photo
Wade Foster
Approve of CEO

Average salary estimate

$110000 / YEARLY (est.)
min
max
$90000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Engineer, AppSec , Zapier

Hey there! We're excited to announce that Zapier is looking for an AppSec Engineer to join our talented Security team in sunny San Francisco. At Zapier, we're all about merging automation with ingenuity, and we believe that your role as an AppSec Engineer is vital in protecting sensitive user data while empowering our development teams to create secure applications. You'll spend about 60-70% of your time diving deep into software development, shaping security practices, and working with cutting-edge technologies like Python, Redis, and AWS. As you step into this role, you'll have the chance to build critical security services that safeguard millions of users worldwide. You'll also collaborate with other teams to conduct threat modeling and vulnerability assessments, ensuring that we don’t just patch individual alarms but block entire vulnerabilities altogether! What’s even cooler? You’ll do all this while enjoying the embrace of a remote-first culture. Being part of Zapier means working with exceptional talents, and you'll have the flexibility and support to grow alongside every team member. We're looking for someone dynamic, passionate about security, and ready to roll up those sleeves! If this sounds like you, don’t hesitate to check us out and see how your career could flourish as we keep humanity at the core of our automations. Let’s make something amazing together!

Frequently Asked Questions (FAQs) for Engineer, AppSec Role at Zapier
What are the main responsibilities of the AppSec Engineer at Zapier?

As an AppSec Engineer at Zapier, you will primarily focus on both software development and security engineering responsibilities. This involves developing core security infrastructure services that encompass key management, encryption, and authentication. You'll also aid in identifying vulnerabilities through collaboration with engineering teams, conducting design reviews, and supporting our public bug bounty program.

Join Rise to see the full answer
What skills are essential for the AppSec Engineer position at Zapier?

The ideal candidate for the AppSec Engineer role at Zapier should possess strong backend development skills in Python, experience with technologies like Redis and PostgreSQL, and a sound understanding of cryptographic principles. Familiarity with distributed systems and platforms such as AWS, coupled with comprehensive knowledge of secure coding practices and the secure development lifecycle, is essential.

Join Rise to see the full answer
How does the AppSec Engineer contribute to Zapier's mission?

The AppSec Engineer plays a significant part in Zapier’s mission to democratize automation while ensuring user security and privacy. You'll help build trust with our users by implementing robust security measures that protect sensitive data, ultimately allowing millions of businesses to leverage automation confidently.

Join Rise to see the full answer
What is the work culture like for an AppSec Engineer at Zapier?

Zapier fosters a diverse and inclusive work environment, emphasizing collaboration, flexibility, and growth. As an AppSec Engineer, you'll work alongside passionate colleagues and have the freedom to adapt to a remote-first culture while contributing to innovative security solutions.

Join Rise to see the full answer
How does the hiring process work for the AppSec Engineer role at Zapier?

Zapier uses a non-standard application process promoting equity and inclusion. Candidates are encouraged to answer several in-depth questions during the application process, which provides insight into their skillset. This streamlines hiring and creates a connection right from the start, helping us understand your potential fit within our security team.

Join Rise to see the full answer
Common Interview Questions for Engineer, AppSec
Can you explain your experience with Python and building production services?

When addressing this question, aim to share specific projects where your use of Python led to successful production services. Highlight any challenges you faced and how you overcame them, demonstrating your technical expertise and problem-solving abilities.

Join Rise to see the full answer
What security vulnerabilities are you most familiar with?

It's beneficial to reference the OWASP Top 10 vulnerabilities. Discuss how you monitor and mitigate these risks through proactive strategies and your approach towards implementing secure coding practices across development teams.

Join Rise to see the full answer
How would you conduct a threat modeling session?

Discuss your process for identifying assets, threats, and vulnerabilities in applications. Walking the interviewer through a previous example can display your ability to apply theoretical knowledge to practical scenarios, making for a convincing argument.

Join Rise to see the full answer
What tools do you use for vulnerability management?

Mention specific tools like SAST or SCA that you’ve successfully used in previous roles. Explain how you leverage these tools to assess, prioritize, and remediate vulnerabilities across applications.

Join Rise to see the full answer
Can you describe your experience with cloud platforms like AWS?

Articulate your hands-on experience with AWS services, detailing how you’ve implemented security controls or built systems on this platform, and ensure you cover compliance and best practices related to cloud security.

Join Rise to see the full answer
How do you ensure your code meets high-quality standards?

Emphasize your commitment to code quality through thorough testing, documentation, and utilizing code reviews. Sharing metrics or examples that showcase your approach can provide solid evidence of your diligence in protecting secure coding practices.

Join Rise to see the full answer
What collaboration experiences do you have with non-security teams?

Collaboration is key in security roles. Share examples of how you’ve effectively communicated security practices to engineering or product design teams, showing both adaptability and strong interpersonal skills.

Join Rise to see the full answer
Discuss a time you identified a security flaw in a product.

Provide a specific example detailing the context, what the flaw was, how you discovered it, and the steps you took to remediate it. This not only shows your proactive approach but also your commitment to security.

Join Rise to see the full answer
What motivates you to work in application security?

Discuss your passion for security and problem-solving, illustrating your aspirations to create secure, trustworthy products. This helps demonstrate your alignment with Zapier’s mission and values.

Join Rise to see the full answer
How do you keep up to date with the latest security trends and best practices?

Mention any relevant resources, forums, or events you engage with to stay informed about developments in application security. Illustrating your commitment to continuous learning can resonate positively with interviewers.

Join Rise to see the full answer
Similar Jobs
Clerk Remote No location specified
Posted 6 days ago

Join Clerk as a Product Engineer and contribute to the development of innovative solutions that enhance the user experience for developers.

Photo of the Rise User
Posted 11 days ago

Join Talan's dynamic team as a Backend Java Developer to innovate Payment Platforms and help shape the future of financial technology.

Photo of the Rise User
Posted 10 days ago

Xello is on the lookout for a Senior Backend Engineer to spearhead innovative projects and optimize backend solutions in the education space.

Photo of the Rise User
Toast Remote Boston, Massachusetts, United States
Posted 8 days ago

Step into a pivotal role as a Senior Software Engineer at Toast, where you’ll spearhead innovations to assist restaurants in maximizing their efficiency and guest experiences.

Photo of the Rise User

ALTER SOLUTIONS seeks a skilled Mid/Senior Angular Developer to enhance their team working on corporate banking product solutions.

Photo of the Rise User
Posted 2 days ago

Visa is looking for a Staff Software Engineer with expertise in .NET and C# to help innovate payment systems on a global scale.

Photo of the Rise User
KBR Hybrid Sioux Falls, South Dakota
Posted 9 days ago

Join KBR as a Software Engineer Intern and engage in dynamic software development while contributing to critical Earth monitoring missions.

Photo of the Rise User
PredictHQ Remote No location specified
Posted 6 days ago

At PredictHQ, be part of an innovative team as a Senior Software Engineer, building systems that revolutionize demand intelligence.

Zapier exists to Make Automation Work for Everyone.

77 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 4, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Associate Manager, CPG Ads & Promotions - S&O at DoorDash USA
Photo of the Rise User
Someone from OH, Cleveland just viewed Manager, Trade Marketing at Red Bull
Photo of the Rise User
7 people applied to Flutter Developer at Adree
Photo of the Rise User
Someone from OH, Cincinnati just viewed Freelance Audio Editor at Side
Photo of the Rise User
Someone from OH, Painesville just viewed Summer Intern at Gooch & Housego
Photo of the Rise User
Someone from OH, Mansfield just viewed Manager, BDR Outbound at Wealthsimple
P
Someone from OH, Cincinnati just viewed Content Writer Intern at Promilo
Photo of the Rise User
Someone from OH, Cincinnati just viewed Content Writer at TKDA
M
Someone from OH, Cincinnati just viewed Freelance English Writer - AI Tutor at Mindrift
Photo of the Rise User
Someone from OH, Cincinnati just viewed Research Analyst / Writer at Crypto.com
P
Someone from OH, Loveland just viewed Undergraduate Administrative Assistant - Biology at PSU
Photo of the Rise User
Someone from OH, Loveland just viewed SEO Copywriter at Flex
Photo of the Rise User
Someone from OH, Loveland just viewed Marketing Manager, Content, Blog and SEO at Okendo
Photo of the Rise User
Someone from OH, Loveland just viewed Social Media Manager at HoneyBook
Photo of the Rise User
Someone from OH, Loveland just viewed SEO Admin & Business Support at Outliant
Photo of the Rise User
Someone from OH, Sunbury just viewed Financial Analyst, FP&A – Tampa, FL at Signode
Photo of the Rise User
100+ people applied to Scrum Master-Remote at DICE
Photo of the Rise User
Someone from OH, Dayton just viewed Data Engineer- Maps at Apple
Photo of the Rise User
35 people applied to Software Engineer Intern at Hudl
Photo of the Rise User
6 people applied to Junior .NET Developer at Optimiza