Senior Security Engineer - AppSec
Pure Storage · Santa Clara, CA · IT
About this role
Pure Storage is hiring a senior-level Application Security Engineer based in Santa Clara, CA. The posting calls out experience with Python, Git, CI/CD, Microservices. Compensation is listed at $186,000–$279,000 per year.
- Role
- Application Security Engineer
- Function
- security
- Level
- senior
- Track
- Individual contributor
- Employment
- Full-time
- Location
- Santa Clara, CA
- Department
- IT
More roles at Pure Storage
Job description
from Pure Storage careersWe’re in an unbelievably exciting area of tech and are fundamentally reshaping the data storage industry. Here, you lead with innovative thinking, grow along with us, and join the smartest team in the industry.
This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.
THE ROLE
As a Senior Security Engineer at Everpure, you will advance the scalability and maturity of application security across the enterprise by designing automated, paved-road solutions rather than acting as a traditional gatekeeper. Embedded within the Global Information Security Office (GISO), you will collaborate closely with product, platform, and engineering teams to integrate security directly into modern software development lifecycles. Your mission is to enable rapid engineering velocity while establishing consistent, robust defense-by-default standards that safeguard our global platform.
WHAT YOU'LL DO
- Own the CI/CD and GitOps security integration lifecycle, building automated, paved-road application security controls (including SAST, DAST, SCA, and secrets scanning) to eliminate manual engineering friction and ensure frictionless, secure-by-default code deployment across all Everpure product teams.
- Develop scalable automation and API-driven tooling using Python to streamline vulnerability detection, compliance reporting, and remediation tracking, directly scaling the operational capability of the GISO without impeding developer velocity.