Staff Application Security Engineer
Agilityrobotics · Remote · 2026-06-10
About this role
<div class="content-intro"><p>Agility’s commercially deployed humanoids operate alongside teams in warehouses, manufacturing facilities, and distribution centers—tackling physically demanding and repetitive tasks while enabling workers to focus on higher-value work. With industry-leading safety standards and years of proven deployment data, we're pioneering a new era of automation that enhances human potential.</p></div><h2><span style="font-size: 12pt;"><strong>About Agility Robotics</strong></span></h2> <p><span style="font-size: 10pt;">Agility Robotics is pioneering the field of humanoid robots, designing systems like Digit to safely and adaptively work alongside people in environments built for people, such as logistics and manufacturing. Our mission is to make businesses more productive and people's lives more fulfilling by delivering robots with advanced mobility, intelligence, and efficiency. To support this rapid scaling, we are currently managing massive growth, expanding our robot fleet from 100 to 1,000 and growing our staff from 300 to 500. This expansion is critical to capitalizing on the humanoid robot market, which is projected to reach $15.3 billion by 2030.</span></p> <p><span style="font-size: 10pt;">Our flagship product is the bipedal robot <strong>Digit</strong> (currently v4), which handles payloads up to 35 pounds, and our cloud-based platform, <strong>Agility Arc</strong>, which allows businesses to deploy, monitor, and scale robot fleets.</span></p> <h2><span style="font-size: 12pt;"><strong>About The Role</strong></span></h2> <p><span style="font-size: 10pt;">As a Staff Application Security Engineer, you will be crucial in integrating security controls directly into our software development lifecycle (SDLC). This role is vital for reducing the exposure of proprietary code and minimizing application-layer vulnerabilities within our robot software, cloud platform (Agility Arc), and internal tools, thereby preventing expensive, post-deployment incidents.</span></p> <p><span style="font-size: 10pt;">You will join a growing Security and Networking team focused on securing a tenfold increase in our network and application attack surface, while preparing the company for external compliance initiatives like SOC 2 and ISO 27001.</span></p> <h2><span style="font-size: 12pt;"><strong>Key Responsibilities</strong></span></h2> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Security Development Lifecycle (SDLC) Integration:</strong> Drive the implementation of security practices throughout the entire software development process, from design review through deployment.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Application Security Testing:</strong> Perform offensive penetration testing and defensive (Blue Team) testing on web applications, internal services, and robot-side software to identify and remediate vulnerabilities.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Automation and Tooling:</strong> Implement and manage security tools, including Static Application Security Testing (SAST) or Dynamic Application Security Testing (DAST) or runtime vulnerability assessments, and Software Bill of Materials (SBOM) systems. Implementation of these systems using tools such as JFrog Artifactory, GitHub Advanced Security, Datadog, Wiz or Snyk.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Code Review and Governance:</strong> Define and enforce security policies for source code, including mandatory GitHub security practices and review procedures.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Vulnerability Management:</strong> Manage the lifecycle of identified vulnerabilities, prioritizing remediation efforts based on risk to the fleet, proprietary code, and cloud infrastructure.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;"><strong>Collaboration:</strong> Partner with development, platform, and infrastructure teams to ensure security requirements are met without hindering engineering velocity.</span></li> </ul> <h2><span style="font-size: 12pt;"><strong>Required Qualifications</strong></span></h2> <ul> <li style="font-size: 10pt;"><span style="font-size: 10pt;">8+ years of dedicated, hands-on experience in Application Security (AppSec) engineering or a related Staff-level security role.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Demonstrated expertise in Application Security engineering with programming skills.</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Proven hands-on experience implementing security controls in CI/CD pipelines and source control systems (e.g., GitHub, GitLab).</span></li> <li style="font-size: 10pt;"><span style="font-size: 10pt;">Experience with penetration testing, vulnerability scanning and offensive and defensive security (Red Team/Blue Team) practices.</span></li> <li style="font-size: 10pt;"><span…
Skills asked for
- penetration testing
- datadog
- ci/cd
- python
- go
- c++
- aws
- gcp
Similar jobs
- Staff Applications EngineerAntora · Remote
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.