ninjaone

Senior Software Engineer | Application Security Engineering

United States · Posted today

Opens app.jobvite.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Full-time
Work mode
Not specified
Source
Jobvite (employer's hiring system)

Skills mentioned

AWS, C++, LLM, Python, Java, Kotlin, Distributed Systems, Threat Modeling

About the role

About the Role

NinjaOne’s Application Security Engineering team is looking for a Senior Software Engineer to assist in building an AI platform that discovers vulnerabilities in production code, validates findings against real attack paths, and proposes tested fixes. You will build and own the software that makes this work reliable at scale, partnering with Security Architecture and Product Engineering to turn security research into actionable improvements across our cloud platform and endpoint agents.

 

This is a hands-on software engineering role with ownership from design through production. You will solve problems in agent orchestration, durable execution, context management, evaluation, and cost control. Your work will help engineers find and fix meaningful vulnerabilities earlier, with evidence they can trust.

 

We are hiring four engineers across two focus areas: Vulnerability Discovery and Finding Validation, with two openings in each. We will discuss your preference during interviews. Discovery develops and tests vulnerability hypotheses; Validation independently challenges findings and develops evidence-backed fixes. Separate model families and independent ownership help each stage check the other’s conclusions.

 

Location - We are flexible on remote working from home, if you are located in the USA and reside in one of the following states - CA, CO, CT, FL, GA, *IL, KS, MA, MD, ME, NJ, NC, NY, OH, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option.

 

*Onsite interviews may be required for this role.

 

We hire the best software engineers, but experience in our stack can’t hurt: NinjaOne is built on Java, Kotlin, C++, Golang and Postgres; supporting millions of user endpoints and running as a scalable cloud service in AWS.  Knowing large-scale datastore bottlenecks, asynchronous application design and client-server architecture will help you.

 

What You’ll be Doing

  • Build and operate a production AI vulnerability platform with resumable workflows, bounded agent execution, model routing, and per-repository budgets across AWS Bedrock and OpenAI-compatible APIs.
  • Engineer repository context, threat models, and coverage tracking so agents can reason about entry points, trust boundaries, tenant isolation, and relevant code paths.
  • Build independent validation, stable finding identity, and deduplication. Ground reachability and exploitability of judgments in code, deployment evidence, and reproducible tests.
  • Develop patch and regression-test workflows that demonstrate a failing test before a fix and a passing test afterward, check for regressions, and require human review before merging.
  • Protect agent execution with sandboxing, least-privilege tool access, and controls for untrusted repository content, prompt injection, secrets, and sensitive data.
  • Partner with security and engineering teams to deliver findings through SARIF and existing workflows. Measure validated finding quality, coverage, reliability, and cost per validated finding; communicate results and share engineering practices.
  • Other duties as needed

 

About You

 

  • 5+ years of software engineering experience, including ownership of production services or automation platforms, and hands-on experience building LLM-backed applications or agent workflows.
  • Strong Python skills, including asynchronous concurrency, typing, testing, packaging, and profiling. You can design, ship, debug, and maintain production-quality software.
  • Experience building multi-step workflows with durable state, idempotent retries, task queues, termination conditions, observability, and resource limits. You can explain the failure modes and tradeoffs of systems you have shipped.
  • Hands-on experience with LLM APIs, tool calling, structured outputs, context management, and evaluation. You can assess when to use an agent framework and when simpler orchestration is more reliable.
  • Experience with AWS or comparable cloud infrastructure and distributed systems. Familiarity with model provider integrations, container isolation, and secure handling of code and credentials.
  • Working knowledge of application security, including authentication, authorization, common vulnerability classes, and trust boundaries. You can use evidence to distinguish a plausible hypothesis from an actionable finding.
  • Ability to work through ambiguity, collaborate with product and security engineers, and communicate technical decisions and results to engineering and leadership audiences.
  • Bachelor’s degree in Computer Science, Information Technology, or a related field, or equivalent practical experience.

 

Focus area experience

You do not need expertise in both areas. We are interested in depth aligned with the work you want to own.

  • Vulnerability Discovery: static analysis, syntax trees and call graphs, code retrieval, threat modeling, or sandboxed proof-of-concept execution. Experience reading C or C++ and understanding native-code vulnerabilities is valuable for our endpoint agents.
  • Finding Validation: security triage, clustering or near-duplicate detection, benchmark design, ground-truth labeling, or automated patching and test infrastructure. You understand how to measure precision and the limits of recall estimates without a labeled dataset.

 

Additional experience that would be useful

  • SARIF, SAST/SCA integrations, durable execution frameworks, or tracing and evaluation tools for LLM applications.
  • Securing agentic systems through authorization, sandboxing, tool permissions, or defenses against malicious inputs.
  • Open-source contributions, security research, program repair, or other examples of software you have built and operated.

 

 

 

About Us 

NinjaOne unifies IT to simplify work for nearly 40,000 customers in 140+ countries. ​

The NinjaOne Unified IT Operations Platform delivers endpoint management, autonomous patching, backup, and remote access in a single console to improve efficiency, increase resilience, and reduce spend. By automating IT and managing all endpoints, organizations give employees a great technology experience at work. ​ NinjaOne is obsessed with customer success and has retained a 98% customer satisfaction score for more than 5 years.

 

What You’ll Love 

We are a collaborative, kind, and curious community. 

We honor your flexibility needs with full-time work that is hybrid remote.

We have you covered with our comprehensive benefits package, which includes medical, dental, and vision insurance.

We help you prepare for your financial future with our 401(k) plan.

We prioritize your work-life balance with our unlimited PTO.

We reward your work with opportunity for growth and advancement.

 

Additional Information

This position is NOT eligible for Visa sponsorship.

 

*Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

 

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington the base salary hiring range for this position is $170,000 - $230,000 per year.

 

For roles based in New York, the base salary hiring range for this position is $170,000 - $230,000 per year.

 

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.

 

 

#LI-MM1

#LI-Remote

#LI-Hybrid

#BI-Remote

#BI-Hybrid

 

 

Job ID jv-ninjaone-o73rafwl-cybmyfwd · Original posting ↗