This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Staff Application Security Engineer at Confluent, you will join a team of security architects and engineers responsible for shaping and advancing the application security strategy across our on-premises products and cloud services. In this role, you will go beyond implementation to define the long-term security posture of our ecosystem, spanning high-scale distributed systems, on-prem deployments, and globally operated cloud platforms.
Job Responsibility:
Partner closely with Engineering, Product, and Platform teams to identify security risks early, influence architectural decisions, and drive adoption of secure-by-design practices
Define and standardize threat modeling frameworks and security design standards, and lead security design reviews for complex, distributed systems
Serve as the subject matter expert (SME) for product security implementation reviews, overseeing security code reviews and API security testing
Architect and drive the roadmap for security automation, building scalable software security tooling
Design and lead the deployment of automation and orchestration frameworks that integrate security seamlessly into the cloud-native deployment pipeline
Proactively identify new vulnerability classes, lead research initiatives and orchestrate complex table-top exercises
Strategically identify and deploy advanced technology controls to maximize observability and harden key attack surfaces
Requirements:
10–12 years of hands-on Application Security experience
Comprehensive knowledge of security fundamentals as applied to modern web applications and cloud-native platforms including secure software design and architecture, secure coding practices, common vulnerability classes
Ability to partner as a trusted peer with Engineering and Product leadership
Ability to lead technical investigation and response to application security incidents
Proven experience evolving the software development lifecycle to embed security by default
Experience in Go, Python, or Java, with the ability to design and build scalable security automation frameworks
Experience in leading cross-functional initiatives in distributed environments
A data-driven decision-maker who can balance security requirements with business velocity and engineering trade-offs
Ability to raise the organization’s security bar through architectural reviews, advanced technical guidance, and the development of engineers
Nice to have:
Passionate about applying AI and LLMs to automate complex security workflows, reduce manual toil, and drive measurable improvements in security outcomes