SECTION I · THE BRIEF
Brief #51505Updated 22 AUG 2026SAN FRANCISCO, CAYcY COMBINATOR
Employbl Company Profile

Senior Application Security Engineer

Zip provides one place for any employee to initiate a purchase or vendor request. Each request is correctly routed for approval across procurement, finance, IT, data security, legal, and other teams, and Zip integrates…

Location
San Francisco, CA
Company size
200–1,000
Posted
1w ago
Via
Yc
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Zip logo

Senior Application Security Engineer · Zip

View company profile
Job title
Senior Application Security Engineer
Job location
San Francisco, CA, US
Job description
The **Security team** at Zip is responsible for protecting the confidentiality and integrity of our customers’ data. As our **first Application Security Engineer**, you will take on a dynamic and high impact role. You will lead our efforts to build foundational security guardrails, launch key security initiatives, and solidify trust customers place in us. Your contributions will be pivotal to the success of Zip’s rapid growth as we launch new products, such as AI Agents and an App Marketplace, and enter into new markets, including EMEA and the Federal government space. We move quickly to solve a wide range of complex technical and product challenges. While we are an experienced team that can provide constant guidance and mentorship, we value engineers who can autonomously scope and solve complex technical challenges. **You will** * Design and implement technical controls to eliminate or mitigate classes of security vulnerabilities. * Support the development of secure products through design reviews, threat models, static/dynamic scans, and hands-on security assessments. * Validate, triage, and coordinate security findings from bug bounty and third party pentests. * Mentor security analysts and security champions on security best practices and techniques. **Qualifications** * Experience writing production-quality code for security tooling and services * Strong written and verbal communication with internal and external stakeholders * A solid understanding of security risks and the ability to balance security with business requirements * Experience with web applications, APIs, and cloud environments. At Zip, our stack includes Python, React, GraphQL, Kubernetes, and AWS **Nice to haves** * Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP * Hands-on experience in offensive security (eg, through bug bounty programs or CTFs)
View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Where this role is based

San Francisco, CA

Loading map…

Zip headquarters

San Francisco, CA

Company size

2001,000 employees

Founded

2020

Total raised

$371,325,000

View company profile ↗

Funding rounds