Senior Application Security Engineer

Who We Are

Cobalt provides the world's largest pentesting platform, delivering thousands of pentests per year. Cobalt's Pentest as a Service (PtaaS) platform is modernizing traditional pentesting. By combining a SaaS platform with an exclusive community of testers, we deliver the real-time insights you need to remediate risk quickly and innovate securely. We see the Pentest as a Service model as a first step in our vision to create a new interface to the security workforce. We have seen tremendous traction over the years and today we have 1000+ customers on Cobalt's platform, ranging in size from Fortune 50 companies to emerging tech start-ups.

We are remote-first with local hubs in Austin, Boston, Berlin, and San Francisco. We have Scandinavian roots, an American base and a global outlook. Our team is characterized by a fun, fast-paced and collaborative culture based on individual responsibility and ownership.

We have secured more than $50M in funding from a variety of top flight investors, led by Highland Europe. We are using our funding to expand global usage and continue development of the Cobalt platform, which pioneered the Penetration test as a Service (PtaaS) model.


This position will be accountable for establishing and maintaining the Application Security Program for our customer facing platform that is used for PtaaS (Pentest as a Service). You’ll focus on designing, building, and deploying application security tools to protect our platform.

It involves scheduling penetration tests, Bug Bounty program, ensuring remediation of discovered vulnerabilities, application security collaboration with engineering teams. If you’re a creative problem solver who is aiming to go beyond your limits, and willing to take your career to the next level here in the US, then this is the right place for you.

What You'll Do

  • Perform dynamic application security testing (DAST).
  • Perform static analysis (SAST) of the micro-services and Web applications codebase.
  • Discover, prioritise, and help remediate technical risks on features, products, and infrastructure.
  • Perform threat assessment on existing and upcoming features and releases.
  • Develop and own best practices for application security, development, and deployment (CI/CD).
  • Identify and assess vulnerabilities stemming from third party dependencies.
  • Collaborate with other engineers, PMs, and designers.

You Have

  • Minimum of 6 years of experience with any combination of the following: threat modeling experience, secure coding, software development, cryptography and network security.
  • Experience with industry standard threat models and security tooling.
  • Deep understanding of web security, TLS/SSL, web authentication and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols).
  • Experience with web applications, SaaS environment and micro-service architecture.
  • Proven track record securing highly available and highly scalable systems.
  • Familiarity with one or more cloud vendor services and management tools (AWS, GCP).
  • Team player who can get along with others both inside and outside the company.
  • Experience with vulnerability management

Bonus If You Have

  • Experience with SAST tools like Checkmarx, Snyk
  • Experience with Infrastructure security

Diversity at Cobalt

With over 45 nationalities already at Cobalt (and counting) we respect and celebrate diversity! We’re proudly committed to equal employment opportunities regardless of your gender, religion, age, sexual orientation, ethnicity, disability, or place of origin. We support each other and are grateful for each Cobalter's contribution to our mission — let's make security dance!

Please apply even if you don't think you meet all of the criteria above but are still interested in the job. Nobody checks every box, and we're looking for someone excited to join the team.

Why You Should Join Us

  • Grow in a passionate, rapidly expanding industry operating at the forefront of the Pentesting industry
  • Work directly with experienced senior leaders with ongoing mentorship opportunities
  • Earn competitive compensation and an attractive equity plan
  • Save for the future with a 401(k) program (US)
  • Benefit from medical, dental, vision and life insurance (US)
  • Leverage stipends for:
    • Wellness
    • Work-from-home equipment & wifi
    • Learning & development
    • Unlimited books
  • Treat yourself to paid remote lunches
  • Make the most of our flexible, generous paid time off
  • Work remotely from anywhere in the US
  • Explore the world with our travel bonus payouts at your 2, 3, and 5 year anniversary
Apply now
Penetration Testing
View company profile


Fully flexible hours

Dog friendly