layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
remote
Source: Quanata careers · View original posting
From Quanata's posting. “We” and “our” refer to the employer.
To help keep everyone safe, we encourage all applicants to pay close attention to protect themselves during their job search. When applying for a position online you are at risk of being targeted by malicious actors looking for personal data. Please be aware we will only reach out via email using the domain quanata.com. Anything that does not match those domains should be ignored and considered a security risk.
Quanata is on a mission to help ensure a better world through context-based insurance solutions. We are an exceptional, customer centered team with a passion for creating innovative technologies, digital products, and brands. We blend some of the best Silicon Valley talent and cutting-edge thinking with the long-term backing of leading insurer, State Farm.
Learn more about us and our work at quanata.com
Our Team
Quanata, LLC is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions, develops risk-focused acquisition capabilities, and builds/supports a full-stack, flexible, digital & increasingly AI-native insurance platform. This helps our primary clients, State Farm and HiRoad Assurance Company, adapt to evolving market needs. Quanata, LLC is wholly owned and funded by State Farm.
As a company that prioritizes an inclusive and positive culture, we believe the core of our success is in hiring talented people — across disciplines — who want to help us make a quantifiable impact.
As a Senior Application Security Engineer
, you’ll be a key security partner to our web and backend engineering teams, helping build security into every stage of the software development lifecycle.
You’ll work closely with a product portfolio to guide product security, with particular emphasis on AI/ML security considerations and collaboration with data science teams. From secure design and threat modeling to code reviews and vulnerability remediation, you’ll help engineering teams identify and address security risks early.
This role is ideal for someone who combines deep application security expertise with a developer-focused mindset. You’ll bridge frontend, backend, and API security while helping engineers solve complex security challenges and strengthen secure development practices across the organization.
Your Day-to-Day
Partner with a product portfolio to manage product security, with a strong emphasis on AI/ML automation, security consulting and cross-functional collaboration with non-portfolio teams.
Lead security design reviews and threat modeling for APIs, web features, and service integrations.
Integrate security tooling—including SAST, SCA, and DAST—into CI/CD pipelines and developer workflows.
Review source code and deployment configurations to identify security vulnerabilities, and partner with developers to triage, remediate, and validate findings.
Support secure development practices across engineering teams, including maintaining AppSec guidance and contributing to security awareness and enablement.
Develop and deploy AppSec automation and integrations, utilizing AI/ML as possible, including ASVS scanning and Burp Suite Enterprise.
Support application security integration reviews, SaaS security assessments, and open-source software reviews.
Participate in cross-functional incident response and remediation planning.
Experience & Education
Bachelor’s degree or equivalent relevant experience.
6–8 years of experience in application security or full-stack development with security expertise.
Technical Skills
Strong understanding of secure coding practices in Python, JavaScript/TypeScript, Node.js, and web standards.
Familiarity with application risks and vulnerabilities, including the OWASP Top 10 (web and GenAI LLM), API security, SSRF, and related security concerns.
Experience with code scanning tools such as CodeQL, Wiz, SonarQube, or Snyk.
Comfortable reading and debugging complex codebases across the technology stack.
Professional Skills
Clear and thoughtful communicator who can effectively guide engineers at all levels.
Bonus Points
Experience with GraphQL security.
Participation in security champions programs or secure SDLC rollouts.
Contributions to open-source security tooling.
Familiarity with infrastructure-as-code and container security.
Experience automating,security, and developing with AI/ML.
Salary: $232,000 to $379,000
*Please note that the final salary offered will be determined based on the selected candidate's skills, and experience, as well as the internal salary structure at Quanata. Our aim is to offer a competitive and equitable compensation package that reflects the candidate's expertise and contributions to our organization.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted:
Clera · San Francisco, California, United States
Clera · San Francisco, California, United States
Clera · San Francisco, California, United States
Clera · San Francisco, California, United States
Clera · San Francisco, California, United States
xai · Palo Alto, CA; Austin, TX; New York, NY; Seattle, WA