
Sr. Security Engineer
Salt Lake City, UT · HybridJobSeen 1w agoSeen in employer's feed 3 days ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Salt Lake City, UT, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
Lucid Software seeks a Senior Application Security Engineer to embed security throughout the development lifecycle, partnering with product and engineering teams. The role involves conducting architecture reviews, mentoring engineers, advancing the Secure Software Development Lifecycle, and addressing AI‑related security risks, all within a hybrid work environment that balances remote and office collaboration.
Skills & qualifications
Skills
Qualifications
Full job description
Lucid Software is the leader in AI-driven work acceleration, helping teams see and build the future by turning ideas into reality. Its products include the Lucid Visual Collaboration Suite (Lucidchart and Lucidspark) and airfocus. The Lucid Visual Collaboration Suite, combined with powerful accelerators for cloud and process transformation, empowers organizations to streamline work, foster alignment, and drive business transformation at scale. We hold true to our core values: innovation in everything we do, passion & excellence in every area, individual empowerment, initiative and ownership, and teamwork over ego. At Lucid, we value diverse perspectives and are dedicated to creating an environment and culture that is respectful and inclusive for everyone. Lucid is a hybrid workplace. We promote a healthy work-life balance by allowing employees to work remotely, from one of our offices, or a combination of the two depending on the needs of the role and team.
As a Senior Application Security Engineer at Lucid, you will be a trusted security partner embedded in the heart of our development lifecycle. You'll work closely with engineering, product, and corporate teams to build security in from the start.
Lucid's customers trust us with their data, and that trust is foundational to our mission. A successful Senior Application Security Engineer combines deep technical knowledge with strong relationship-building skills, enabling product teams to move fast without taking on undue risk.
Responsibilities:
-
Conduct thorough security architecture and design reviews for new and evolving product features, surfacing risk early and recommending practical mitigations.
-
Drive a risk-based approach to application security, helping teams understand and prioritize vulnerabilities by business impact.
-
Serve as a subject matter expert on application security topics for product, engineering, legal, and leadership stakeholders.
-
Mentor engineers across the organization on secure development practices, fostering a culture where security is everyone's responsibility.
-
Build and maintain strong, collaborative partnerships with product and engineering teams, serving as their primary security resource and advocate throughout the software development lifecycle.
-
Mature Lucid's Secure Software Development Lifecycle (SSDLC), including secure coding standards, security requirements, and developer security education.
-
Ensure AI tools and processes are implemented within acceptable risk limits.
-
Lead product design reviews to ensure security considerations are inherent in feature design.
-
Develop and maintain scalable security tooling and automation to integrate security controls into CI/CD pipelines with a focus on reducing risk over implementing tools.
-
Lead and train engineers in Lucid’s security champions program.
Requirements:
-
5+ combined years of experience in software engineering, application security, product security, or a closely related field within a SaaS environment.
-
Proven track record of building trusted, effective relationships with product and engineering teams.
-
Experience securing web applications built on modern frameworks and cloud-native architectures (particularly AWS).
-
White-box penetration testing experience.
-
Strong understanding of SSDLC principles and experience implementing or maturing secure development programs.
-
Ability to conduct meaningful security architecture and design reviews, with a focus on identifying risk early in the development process.
-
Solid understanding of common application vulnerabilities and attack techniques (OWASP Top 10, API security, authentication/authorization flaws, etc.).
-
Experience integrating security tooling into modern CI/CD pipelines.
-
Risk-focused mindset: able to articulate security risk in business terms and help teams make informed, pragmatic decisions while avoiding security theater.
-
Familiarity with AI security risks and emerging attack surfaces, including securing agentic systems, MCP, and LLM-powered workflows against new and evolving threats.
-
Strong written and verbal communication skills; equally comfortable in a design review with engineers and a risk conversation with leadership.
Preferred Qualifications:
-
Development experience in modern tech stacks.
-
Practical knowledge of relevant security frameworks and compliance standards (e.g., OWASP ASVS, NIST 800-53, SOC 2, GDPR).
-
Relevant certifications such as OSCP, BSCP, GWEB, PNPT, or similar hands-on security-focused certifications.
-
Experience with bug bounty program management.
-
Bachelor's degree in Computer Science, Information Security, or a related field.
#LI-DA1
We welcome diversity at Lucid and are dedicated to creating an environment and culture that is respectful and inclusive for everyone. We honor and support varying backgrounds, beliefs, and perspectives for the benefit of our business, our employees and our products. Lucid is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. If you have a disability and you believe you need a reasonable accommodation in order to search for a job opening or to submit an online application, please email: [email protected].
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
- Chief Information Security Officer AD-2210-00 (Senior Manager) FPL AD-00Department of Education Headquarters · Remote · US · $179–210K/yrPosted 1w agoPosted 1w ago
Manager, AI-Native Security OperationsBambooHR · UT (Hybrid)Posted 2w agoPosted 2w ago
Sr. Agentic EngineerBambooHR · Remote · USPosted 1w agoPosted 1w ago
Personnel Security SpecialistInterior, Bureau of Indian Affairs · Salt Lake City, UT · $62–116K/yrPosted 2 days agoPosted 2 days ago
Deployed Architect, Professional Services (Remote)LangChain · Remote · US · $170–270K/yrPosted todayPosted today
You've read the whole posting — now see how you match it.