Senior Software Engineer, Application Security
Decagon · San Francisco
- Compensation
- $200k - $330k/yr
- Location
- San Francisco
- Employment
- Full time
- Level
- Senior
- Posted
- 5 weeks ago
About a minute 25 sent a week, free No card
- I read this posting
- Rewrite your resume against it
- Draft the cover letter, score the fit
Prefer Decagon’s own form? Open the original posting
About this role
About Decagon
Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experiences.
Our technology enables industry-defining enterprises like Avis Budget Group, Block’s Cash App and Square, Chime, Oura Health, and Hunter Douglas to deploy AI agents that power personalized, deeply satisfying interactions across voice, chat, email, SMS, and every other channel.
We’re building a future where customer experiences are being redefined from support tickets and hold music to faster resolutions, richer conversations, and deeper relationships. We’re proud to be backed by world-class investors who share that vision, including a16z, Accel, Bain Capital Ventures, Coatue, and Index Ventures, along with many others.
We’re an in-office company, driven by a shared commitment to excellence and velocity. Our values - Just Get It Done, Invent What Customers Want, Winner’s Mindset, and The Polymath Principle - shape how we work and grow as a team.
About the Team
The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with trust while defending against sophisticated, AI-enabled threats at massive scale.
Our mission is to provide magical support experiences - ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.
About the Role
Lead the application security strategy and implementation for Decagon AI's conversational platform that serves enterprise customers at scale. You'll partner with engineering teams to build security directly into our AI-powered applications, ensuring protection against application-layer threats while maintaining the performance and reliability our customers expect. This role offers the opportunity to apply deep application security expertise to AI systems and shape security practices across our rapidly growing engineering organization.
In this role, you will
Design and implement application security controls across our AI agent platform, including secure coding practices, threat modeling, and vulnerability management.
Collaborate closely with product engineering teams to integrate security throughout the software development lifecycle, from design, coding, PR, and deployment
Establish application security testing programs including static analysis (SAST), dynamic analysis (DAST), and interactive testing (IAST) tailored for AI applications
Lead security code reviews and architecture assessments for new features, with special focus on AI model integration points and customer data handling
Build security tooling and automation to enable developers to identify and remediate vulnerabilities quickly while maintaining development velocity
Respond to security incidents involving application vulnerabilities, coordinating remediation efforts and post-incident improvements
Your background looks something like this
Have 5+ years of hands-on application security engineering experience
Expertise in secure software development practices, including threat modeling, secure code review, and vulnerability assessment
Strong software engineering background with ability to review code across multiple languages and frameworks commonly used in AI/ML applications
Experience implementing application security testing tools and integrating security into CI/CD pipelines
Knowledge of OWASP Top 10, common application vulnerabilities, and modern application security frameworks
Proven track record working with engineering teams to remediate security findings while balancing security and business requirements
Even better
Experience securing AI/ML applications, including prompt injection, model extraction, and adversarial input protections
Background with large-scale, multi-tenant SaaS applications handling sensitive customer data
Familiarity with Google Cloud application security services and container security best practices
Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an application security perspective
Experience with modern security tools like Semgrep, CodeQL, Cursor Bug Bot, XBOW, or similar
Compensation
$200K - $330K + Offers Equity
Benefits
We proudly offer the following benefits for our full-time employees:
Medical, Dental, and Vision benefits for you and your family
Life Insurance and Disability Benefits
Retirement Plan (e.g., 401K, pension)
Parental Leave
Fertility and family building benefits through Carrot
Monthly stipend to support your wellness, lifestyle, and work-life balance
Daily lunches and snacks in the office to keep you at your best
Take what you need vacation policy (subject to local requirements; UK employees receive 25 days of statutory leave)
These benefits are described in more detail in Decagon’s policies, may vary by location, and can change at any time according to applicable compensation and benefits plans.
As published by Decagon. Applications are handled on their site.
About Decagon
Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experiences. Our technology enables industry-defining enterprises like Avis Budget Group, Chime, Oura Health, 1-800-FLOWERS.COM, and Hunter Douglas to deploy AI agents that power personalized, deeply satisfying interactions across voice, chat, email, SMS, and every other channel. We’re building a future where customer experiences are being redefined from support tickets and hold music to faster resolutions, richer conversations, and deeper relationships.
All 140 openings at DecagonOne click, then it is written
Apply to Decagon with a resume written for this role.
Queue Senior Software Engineer, Application Security and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Decagon’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Decagon
See all- 2 days ago
- 2 days ago
- 2 days ago
- Last week
- Last week
- Last week
Similar roles elsewhere
See more- Today
Manager, Software Engineering - Observability
FigmaSan Francisco, CA • New York
$258k - $376k/yrManagerEngineering - Today
Staff Software Engineer, Autonomous Freight Systems
FlexportSan Francisco, California
$197k - $246k/yrStaffEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Decagon publishes. Refolk is not the employer and does not handle their hiring. Applications go to Decagon directly.