Senior Application Security Engineer

zipยท Engineering
Apply Now โ†—
๐ŸŒ Remote๐Ÿ“ San FranciscoFullTime

About this role

About Zip

Zip is the AI platform for enterprise procurement โ€” built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before.

The worldโ€™s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together theyโ€™ve saved over $8 billion and processed over $500 billion in spend. Zipโ€™s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA.

Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups.

The Security team at Zip is responsible for protecting the confidentiality and integrity of our customersโ€™ data. As our first Application Security Engineer, you will take on a dynamic and high impact role. You will lead our efforts to build foundational security guardrails, launch key security initiatives, and solidify trust customers place in us. Your contributions will be pivotal to the success of Zipโ€™s rapid growth as we launch new products, such as AI Agents and an App Marketplace, and enter into new markets, including EMEA and the Federal government space. We move quickly to solve a wide range of complex technical and product challenges. While we are an experienced team that can provide constant guidance and mentorship, we value engineers who can autonomously scope and solve complex technical challenges. Please note, we cannot offer sponsorship for this role.

You will

  • Design and implement technical controls to eliminate or mitigate classes of security vulnerabilities.

  • Support the development of secure products through design reviews, threat models, static/dynamic scans, and hands-on security assessments.

  • Validate, triage, and coordinate security findings from bug bounty and third party pentests.

  • Mentor security analysts and security champions on security best practices and techniques.

Qualifications

  • Experience writing production-quality code for security tooling and services

  • Strong written and verbal communication with internal and external stakeholders

  • A solid understanding of security risks and the ability to balance security with business requirements

  • Experience with web applications, APIs, and cloud environments. At Zip, our stack includes Python, React, GraphQL, Kubernetes, and AWS

Nice to haves

  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and FedRAMP

  • Hands-on experience in offensive security (eg, through bug bounty programs or CTFs)

The salary range for this role is $160,000 - $240,000. The salary for this position is determined based on a variety of job-related factors that may include location, relevant experience, education, or particular skills and expertise.

Perks & Benefits

At Zip, weโ€™re committed to providing our employees with everything they need to do their best work.

  • ๐Ÿ“ˆ Start-up equity

  • ๐Ÿฆท 100% health, vision & dental coverage options

  • ๐Ÿฝ๏ธ Catered breakfast, lunch, & dinner

  • ๐ŸŒด Flexible PTO

  • ๐Ÿ‹๏ธโ€โ™€๏ธ ClassPass membership

  • ๐Ÿš Monthly commuter benefit

  • ๐Ÿš  Team building events & happy hours

  • ๐Ÿ’ป Home office stipend

  • ๐Ÿ›œ Phone/internet reimbursement

  • ๐Ÿผ Paid parental leave

  • ๐Ÿง‘โ€๐Ÿง‘โ€๐Ÿง’โ€๐Ÿง’ Fertility stipend

  • ๐Ÿ’ธ 401k plan

  • ๐Ÿค– Unlimited AI token usage

We're looking to hire Zipsters and that means hiring people who take ownership, communicate openly, have an underdog mindset, and are excited to increase the pace of innovation for every business in the world. We encourage all candidates to apply even if your experience doesn't exactly match up to our job description. We are committed to building a diverse and inclusive workspace where everyone (regardless of age, religion, ethnicity, gender, sexual orientation, and more) feels like they belong. We look forward to hearing from you!

Frequently Asked Questions

Is the salary disclosed for the Senior Application Security Engineer position at zip?
The salary for this Senior Application Security Engineer role at zip is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Is the Senior Application Security Engineer job at zip remote?
Yes, this Senior Application Security Engineer position at zip is remote, with team members based in San Francisco. You can work from home or anywhere in the supported regions.
Is the Senior Application Security Engineer role at zip full-time or part-time?
This is listed as a FullTime position. It is posted as a Senior Application Security Engineer role in the Engineering department at zip.
Which team or department does the Senior Application Security Engineer at zip belong to?
This Senior Application Security Engineer position is part of the Engineering department at zip. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Senior Application Security Engineer position at zip?
Click the "Apply Now" button on this page. You will be redirected to zip's official application portal hosted on ashby where you can submit your application directly.
When was the Senior Application Security Engineer job at zip posted?
This Senior Application Security Engineer position at zip was posted on Jun 8, 2026. Apply as soon as possible โ€” early applications are often reviewed first.
Senior Application Security Engineer
zip
Apply for this role โ†—

You'll be redirected to zip's official application page on Ashby ATS.