Application Security Engineer

Application Security Engineer

Find out more about the vacancy and apply below.

Benchling Jeffy P Banner 3 - App Sec Engineer

About the role

As an Application Security Engineer at Benchling you’ll be joining a team responsible for building a best-in-class security program from the ground up. Our focus is on providing value to the organization by emphasizing real world security and embracing automation to keep up with the company as we experience hypergrowth. We’re looking for engineers who are excited to apply their expertise to our mission of securing some of society's most sensitive data


  • Partnering with both the Product Design and Software Engineering organization's security and privacy initiatives, leading security design reviews, and threat modeling
  • Performing black-box and grey-box penetration testing of our own and partners’ services
  • Performing code reviews of our own and partners’ services and apps including SaaS, PaaS, and mobile
  • Researching new attack vectors and techniques relevant to our space and present findings to both internal and external audiences
  • Collaborating with engineers on the best ways to mitigate vulnerabilities and reduce risk
  • Participating in our incident response and vulnerability remediation efforts
  • Integrating external and internal security tools and automation into development and build environments
  • Developing lightweight SDLC processes to embed into Product Design and Software Engineering workflows
  • Develop secure coding practices and train engineering teams
  • Interface with customers’ security teams when they are scoping and performing security assessments
  • Helping to rapidly scale our team. As a member of the security team, you'll be an integral part of how we mature our own tooling, best practices, engineering processes, and hiring
  • 5-10+ years work experience in an application security or product security role including experience with code reviews, pentesting, and ideally threat modeling
  • Strong communicator with the ability to translate technical security requirements and risks into terms that anyone can understand
  • In-depth experience finding AND fixing web application security vulnerabilities including those found in the OWASP Top 10 and CWE Top 25
  • Relevant development experience in multiple programming languages, preferably: Python, Javascript/Typescript
  • Strong, general knowledge of the browser security model, modern network security, and cloud (AWS ideally) security
  • Experience with vulnerability management and risk assessment processes
  • Technical leadership skills; you enjoy being a tech lead, mentoring technologists, and evangelizing security and privacy
  • Comfortable with complexity in the short term but can build towards simplicity in the long term


Apply Now


Over the next 10 years, biotech will fundamentally rewrite the way we live. Gene editing and cell therapy will dramatically change how we treat cancer and other major illnesses. Biofuels and biomaterials will transform the cars we drive, the clothes we wear, and the makeup of everyday objects. Crop science and synthetic biology will produce sustainable and ethical food. Benchling’s mission is to accelerate the research that propels us towards this future, and magnify its impact, through modern software. 

Every day, scientists around the world use Benchling in their efforts to solve humanity's most pressing problems. For these scientists, Benchling is the central technology they use to conduct their research. 

Benchling was founded by a team of MIT graduates and has raised funding from Benchmark, Andreessen Horowitz, Thrive Capital, and Y Combinator. Our customers include pharmaceutical giants, leading biotechs, and the world's most renowned research institutes.

Find out more about Benchling