Staff Application Security Engineer
Staff Application Security Engineer

Staff Application Security Engineer

Full-Time 54000 - 84000 ÂŁ / year (est.) No home office possible
W

At a Glance

  • Tasks: Secure Webflow’s platform and improve development practices with innovative security solutions.
  • Company: Join a remote-first, creative tech company leading the AI-native Digital Experience revolution.
  • Benefits: Competitive salary, equity, bonuses, and opportunities for professional growth.
  • Why this job: Make a real impact on web security while collaborating with talented engineers.
  • Qualifications: 7+ years in application security and hands-on software development experience required.
  • Other info: Dynamic environment with a focus on continuous learning and emerging technologies.

The predicted salary is between 54000 - 84000 ÂŁ per year.

At Webflow, we’re building the world’s leading AI-native Digital Experience Platform, and we’re doing it as a remote‑first company built on trust, transparency, and a whole lot of creativity. This work takes grit, because we move fast, without ever sacrificing craft or quality. Our mission is to bring development superpowers to everyone. From entrepreneurs launching their first idea to global enterprises scaling their digital presence, we empower teams to design, launch, and optimize for the web without barriers. We believe the future of the web, and work, is more open, more creative, and more equitable. And we’re here to build it together.

We’re looking for a Staff Application Security Engineer to help us level up Webflow’s secure development practices ranging from secure coding and tooling to improving procedures.

About the role:

  • Location: Remote‑first (United States; BC & ON, Canada)
  • Full‑time Permanent Exempt
  • Cash Compensation: Base pay ranges vary by geographic zone: United States – Zone A: $175,000 – $247,000, Zone B: $164,000 – $232,000, Zone C: $154,000 – $217,000. Canada (ON & BC) – CAD 199,000 – CAD 280,000.
  • Eligible for Webflow's company‑wide bonus program. Target amounts are a percentage of base salary and vary by career level.
  • Application deadline: applications accepted on an ongoing basis until position is closed and filled.
  • Reporting to: Manager, Application Security.

As a Staff Application Security Engineer, you’ll…

  • Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem.
  • Bring security best practices to the software development lifecycle.
  • Work as part of a team to champion security standards while balancing business strategies and requirements.
  • Support Webflow’s current and future compliance frameworks.
  • Find security vulnerabilities through grey‑box techniques, and propose solutions at the architecture and code level to mitigate findings.
  • Contribute code and architecture improvements to enable security within Webflow’s application for engineers.
  • Cross‑train entry and mid‑level application security engineers.

In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we’ll help you incorporate them into your role.

About you:

Requirements:
  • BA/BS degree or equivalent experience.

You’ll thrive as a Staff Application Security Engineer if you:

  • You bring 7+ years of application security experience, including hands‑on software development, and have operated as a technical authority in securing high‑complexity, large‑scale applications.
  • You have deep expertise in secure software design, secure coding, and modern web application security, with a proven ability to identify security design flaws and complex business‑logic vulnerabilities, and to drive risk‑based remediation with engineering teams.
  • You regularly lead threat modeling efforts, conduct and oversee advanced penetration testing, and manage third‑party pentests, ensuring findings are clearly documented, communicated, and remediated to completion.
  • You have designed, implemented, and evolved software supply chain security programs, and have owned or led bug bounty programs and major security tooling initiatives, shaping strategy rather than acting solely as a contributor.
  • You have implemented and improved Secure Development Lifecycle (SDLC) processes at scale, including planning, automation, and cross‑org communication, influencing how multiple teams build and ship software securely.
  • You have driven multi‑quarter application security roadmaps and complex security programs, partnering with engineering, product, and platform teams to deliver durable security outcomes.
  • You have led security initiatives within large‑scale solutions, including designing and delivering security features directly into applications (e.g., authorization models, security controls, or admin‑level protections) in close collaboration with engineering and partner orgs.
  • You have experience using and building security solutions that leverage agentic AI, including applying AI coding agents to scale security reviews, detection, and automation responsibly.
  • You have participated in and led response efforts for application security incidents, from triage and containment through remediation and post‑incident improvements.
  • You actively mentor and elevate other application security engineers, and help foster strong security practices and judgment across engineering organizations.
  • You are passionate about security, continuously learning, and able to clearly explain complex security concepts to technical and non‑technical partners to drive alignment and action.
  • Stay curious and open to growth — actively building fluency in emerging technologies like AI to unlock creativity, accelerate progress, and amplify impact.

Our Core Behaviors:

  • Build lasting customer trust. We build trust by taking action that puts customer trust first.
  • Win together. We play to win, and we win as one team. Success at Webflow isn’t a solo act.
  • Reinvent ourselves. We don’t just improve what exists, we imagine what’s possible.
  • Deliver with speed, quality, and craft. We move fast because the moment demands it, and we do so without lowering the bar.
  • Ownership in what you help build. Every permanent Webflower receives equity.

Staff Application Security Engineer employer: Webflow

Webflow is an exceptional employer that champions a remote-first work culture, fostering trust, transparency, and creativity among its team members. With a strong focus on employee growth, Webflow offers opportunities for continuous learning and development, particularly in the field of application security, while also providing competitive compensation and a company-wide bonus program. Joining Webflow means being part of a mission-driven team dedicated to building an open, creative, and equitable future for the web.
W

Contact Detail:

Webflow Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Staff Application Security Engineer

✨Tip Number 1

Network like a pro! Reach out to folks in your industry on LinkedIn or at meetups. A friendly chat can lead to opportunities that aren’t even advertised yet.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repo showcasing your projects and contributions. This gives potential employers a taste of what you can do, especially in application security.

✨Tip Number 3

Prepare for interviews by practicing common questions and scenarios related to application security. We recommend doing mock interviews with friends or using online platforms to get comfortable.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive!

We think you need these skills to ace Staff Application Security Engineer

Application Security
Secure Software Design
Secure Coding
Web Application Security
Threat Modeling
Penetration Testing
Bug Bounty Programs
Secure Development Lifecycle (SDLC)
Security Tooling Initiatives
Risk-Based Remediation
Security Incident Response
Mentoring
Communication Skills
Collaboration

Some tips for your application 🫡

Show Your Passion for Security: When writing your application, let your enthusiasm for application security shine through. Share specific examples of how you've tackled security challenges in the past and what drives you to keep learning in this ever-evolving field.

Tailor Your Application: Make sure to customise your application to highlight your relevant experience and skills that align with the role. Use keywords from the job description to demonstrate that you understand what we're looking for and how you fit into our mission.

Be Clear and Concise: While we love a good story, keep your application clear and to the point. Use bullet points where possible to make it easy for us to see your qualifications and achievements at a glance. We appreciate clarity!

Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to receive your details and ensures you’re considered for the role. Plus, it’s super straightforward!

How to prepare for a job interview at Webflow

✨Know Your Stuff

Make sure you brush up on your application security knowledge. Familiarise yourself with secure coding practices, threat modelling, and the latest vulnerabilities. Be ready to discuss your hands-on experience and how you've tackled complex security challenges in previous roles.

✨Showcase Your Collaboration Skills

Since this role involves working closely with engineering teams, be prepared to share examples of how you've successfully collaborated in the past. Highlight any instances where you’ve championed security standards while balancing business needs, as this will resonate well with the interviewers.

✨Prepare for Technical Questions

Expect some technical questions that dive deep into your expertise. Brush up on your knowledge of secure software design and SDLC processes. You might be asked to solve a hypothetical security issue, so practice articulating your thought process clearly and confidently.

✨Demonstrate Your Passion for Security

Let your enthusiasm for application security shine through. Share your experiences with mentoring others, leading security initiatives, or participating in bug bounty programs. Showing that you’re continuously learning and adapting to new technologies, like AI, will set you apart from other candidates.

Staff Application Security Engineer
Webflow

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

W
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>