Application Security Engineer
Benchling · San Francisco, CA · Engineering
We are rebuilding biotech for the AI era.
When a breakthrough is delayed, the world waits. Getting a molecule from discovery to patients, or a crop from lab to field, involves thousands of slow, manual, disconnected steps. AI has the potential to change this, compressing decades of R&D work into years. But that only happens when clean, structured scientific data and AI are built into how science gets done.
Benchling is the AI platform for biotech R&D. Scientists use Benchling to design experiments, capture structured data, and run AI agents and models directly in their workflows. Over 200,000 scientists around the world trust Benchling to power their most important work, from academic labs to Sanofi, Moderna, and more than half of the world's top 50 biopharma.
ROLE OVERVIEW
As an Application Security Engineer at Benchling you’ll be joining a team responsible for maintaining a best-in-class security program. Our focus is on providing value to the organization by emphasizing real world security and embracing automation. We’re looking for engineers who are excited to apply their expertise to our mission of securing some of society's most sensitive data.
RESPONSIBILITIES
Building and integrating external and internal security tools and automation into development and build environments.
Developing lightweight processes to embed security in the SDLC workflow.
Collaborating with engineers on the best ways to mitigate vulnerabilities and reduce risk.
Performing code reviews of our services and apps.
Partnering with both the Product Design and Software Engineering organization's security and privacy initiatives, leading security design reviews, and threat modeling.
Participating in our incident response and vulnerability remediation efforts.
Developing secure coding and design practices and training engineering teams.
Performing black-box and gray-box penetration testing of our applications and services.
QUALIFICATIONS
2+ years work experience in an application security or product security role including experience with secure code reviews, threat modeling, pentesting, application security tooling and automation.
Strong communicator with the ability to translate technical security requirements and risks into terms that anyone can understand.
Experience finding AND fixing web application security vulnerabilities including those found in the OWASP Top 10 and CWE Top 25.
Experience with at least one scripting language, preferably Python
Knowledge of the browser security model, modern network security, AI and cloud (AWS ideally) security is a plus.
Experience with vulnerability management and risk assessment processes is a plus.
HOW WE WORK
We offer a flexible hybrid work arrangement that prioritizes in-office collaboration. Employees are expected to be on-site 3 days per week (Monday, Tuesday, and Thursday).
#LI-Hybrid
#BI-Hybrid
#LI-CG1
Benchling welcomes everyone.
We believe diversity enriches our team so we hire people with a wide range of identities, backgrounds, and experiences.
We are an equal opportunity employer. That means we don’t discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We also consider for employment qualified applicants with arrest and conviction records, consistent with applicable federal, state and local law, including but not limited to the San Francisco Fair Chance Ordinance.