See all roles

[Remote] Staff Security Engineer, Application Security

Work from home Full-time role Hiring

Note: The job is a remote job and is open to candidates in USA. Homebase is a company that focuses on helping small businesses thrive by providing an everything app for hourly teams. They are seeking a hands-on Staff Security Engineer to lead and shape the Application Security domain, defining the strategy and architectural direction to secure their products while addressing security challenges related to AI-powered features.

Responsibilities

  • Define and execute Homebase’s multi-quarter Application Security roadmap, aligning security initiatives with business objectives and company OKRs
  • Architect secure-by-default patterns, frameworks, and paved roads that developers adopt naturally, removing entire classes of vulnerabilities before they reach production
  • Evaluate emerging security technologies and make build-versus-buy decisions that shape the security platform
  • Drive security and product trade-off decisions at the architectural level, balancing protection with velocity
  • Influence company-wide engineering practices and security investments through data-driven recommendations
  • Lead threat modeling and security architecture reviews for AI-powered features, model training pipelines, and LLM integrations
  • Design and implement security controls specific to AI/ML systems, including prompt injection defenses, model input validation, output filtering, and data pipeline integrity
  • Create AI-powered vulnerability detection and security automation that multiplies the team’s effectiveness
  • Partner with AI engineering teams to establish secure development patterns for model deployment and inference infrastructure
  • Stay ahead of the evolving AI threat landscape and translate emerging risks into practical engineering guidance
  • Build and maintain security tooling and automation that integrates seamlessly into CI/CD pipelines, enabling continuous security validation at scale
  • Own the vulnerability management program: design modern systems for detection, prioritization, tracking, and remediation of security debt across the product portfolio
  • Own the bug bounty and responsible disclosure program, turning external researcher findings into systemic improvements
  • Embed security into the full software development lifecycle through scalable guardrails, automated testing frameworks, and developer-facing documentation
  • Partner with senior leaders across Engineering, Product, and Infrastructure to improve Homebase’s overall security posture
  • Pioneer a security partnership program, mentoring engineers across the organization, and driving a culture of shared security ownership
  • Provide expert guidance during security incidents and lead post-incident analysis to drive systemic improvements
  • Curate and author security guidance, patterns, and training content that raises the security bar organization-wide
  • Influence security decisions at the department and company level; shape how Homebase invests in security capabilities

Skills

  • 10+ years of progressive experience in Application Security or Security Engineering, with demonstrated impact at the Staff or Principal level
  • Deep software engineering experience in production environments, you write code, build tools, and think like an engineer first
  • A proven track record of leading architectural changes and complex cross-team initiatives that reduced security risk at scale
  • Hands-on experience securing AI-native applications, including LLM integrations, model pipelines, or ML infrastructure
  • Strong expertise in web application security, cloud-native security (AWS), and modern DevSecOps practices
  • Proficiency in languages and frameworks relevant to our stack: Ruby, Python, React, and Rails
  • Experience designing and implementing modern vulnerability management systems and embedding security tooling within CI/CD pipelines
  • Exceptional ability to evaluate security trade-offs, make pragmatic risk-informed decisions, and communicate them clearly to technical and non-technical stakeholders
  • Demonstrated curiosity about emerging AI capabilities, with a track record of leveraging new tools to enhance security operations and productivity
  • Experience defining application security strategy and maturity roadmaps for a high-growth, product-driven company
  • A background in building AI-powered security tools or detection systems
  • Speaking experience at security conferences, meetups, or community events
  • Experience with threat modeling frameworks adapted for AI/ML systems

Benefits

  • Stock options + TFSA/RRSP with 4% company match
  • Comprehensive medical, dental, and vision for you and your dependents
  • Flex time off + company holidays + designated focus periods
  • We invest in builders and believe that curiosity shouldn't have a paywall. That means you'll have access to paid AI tools with minimal restrictions, so you can build, experiment, and level up your craft.
  • Maternity/Parental Leave EI top-up support offered (after 6 months of service)
  • Work From Anywhere Month + meeting-free weeks yearly
  • Life insurance + short/long-term disability coverage
  • Meals provided, team offsites, and Customer Days
  • For employees located near one of our office hubs, Tuesday and Wednesday are our in-office collaboration days — a time to move faster as a team, build deeper connections, make better decisions, and build together.

Company Overview

  • Homebase is a software application that provides tools for employee scheduling, time tracking, communication, and task management. It was founded in 2014, and is headquartered in San Francisco, California, USA, with a workforce of 201-500 employees. Its website is http://www.joinhomebase.com.
  • Company H1B Sponsorship

  • Homebase has a track record of offering H1B sponsorships, with 1 in 2025, 3 in 2023, 6 in 2020. Please note that this does not guarantee sponsorship for this specific role.
  • Apply To This Job

    You might like

    [Remote] CQV Senior Project Manager

    Work from home Full-time role

    [Remote] Interconnect and Compute Architect

    Work from home Full-time role

    [Remote] Account Executive, Primary

    Work from home Full-time role

    [Remote] Data Analyst

    Work from home Full-time role

    [Remote] Business Analyst, Investment Technology

    Work from home Full-time role

    [Remote] Field Service Engineer (TEA) – NY/NJ

    Work from home Full-time role

    [Remote] Director, Product Management - Planning, Allocations and Merchandising

    Work from home Full-time role

    [Remote] Financial Analyst

    Work from home Full-time role

    [Remote] Azure Cloud Engineer

    Work from home Full-time role

    [Remote] AI and FSI Developer Technology Engineer - New College Grad 2026

    Work from home Full-time role

    Fund Accountant (Remote)

    Work from home Full-time role

    Client Support Specialist (shift schedule)

    Work from home Full-time role

    Experienced Data Entry Clerk – Remote Opportunity with arenaflex

    Work from home Full-time role

    [Remote] Oracle EPM Consultant

    Work from home Full-time role

    Regulatory Affairs Consultant - CMC Mid-level

    Work from home Full-time role

    Licensed Crisis Counselor - Fully Remote in Doylestown, PA

    Work from home Full-time role

    Remote Data Entry Specialist – Telecommunications Pole Inventory Management (Contract/Temporary)

    Work from home Full-time role

    Commodity Manager - Electronics Sourcing (Passives)

    Work from home Full-time role

    Remote Data Entry Specialist – Work From Home Position | arenaflex E-Commerce & Technology Division

    Work from home Full-time role

    Customer Service Representative (Remote)

    Work from home Full-time role