About the Role
We are seeking a Senior / Staff Application Security Engineer to take ownership of product security. This role involves threat modeling, hardening the application layer, and establishing the AppSec practice from the ground up, ensuring our code, APIs, and services are secure by design.
Responsibilities
- Execute application security end to end, including threat modeling features and services, and driving remediation of significant risks.
- Secure the application layer against critical vulnerabilities such as injection, broken authentication and authorization, and insecure APIs.
- Build and manage a secure SDLC, encompassing code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.
- Harden authentication, authorization, and session/identity handling across the product.
- Secure the AI-specific application surface, including model and inference endpoints, prompt and input handling, and new vulnerability classes associated with generative features.
- Collaborate with product and platform engineering to integrate security early in the design process and elevate the security standard of the codebase.
- Establish the standard for how engineering teams reason about and ship secure code.
Requirements
- 6+ years of experience in security engineering with deep, hands-on application security expertise.
- Strong understanding of vulnerability classes that cause incidents and methods to eliminate them at the source (code, API, and authorization design).
- Proven ability to build AppSec practices and secure SDLC tooling, not just operate established ones.
- Proficiency in modern application stacks and comfort working in AWS.
- Ability to collaborate effectively with engineers and improve security without causing blockers.
- Capability to write and ship production-quality code, beyond just code reviews.
- Curiosity about emerging AI/LLM threat classes and defense strategies as the product evolves.
- Nice to have: Experience with consumer products at scale, secure-by-design work on generative AI or ML product surfaces, and/or early security hire experience.
- Applicants must be eligible to work in the US.
Skills
- Application Security
- Threat Modeling
- Secure SDLC
- SAST/DAST
- Dependency Security
- Supply Chain Security
- Secrets Management
- Authentication
- Authorization
- API Security
- AWS
- Production Code Development
- AI/LLM Security
Location
- Onsite
Work Type
- Full-time
- Onsite
Experience Level
- Senior
- Staff
Salary/Compensations
- $230,000 to $330,000
Benefits
- Company Equity Package
- 401(k) with 3% Employer Match & Roth 401(k)
- Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options)
- 11 Paid Holidays + Unlimited PTO & Sick Time
- 16 Weeks of Paid Parental Leave
- Creative Education Stipend
- Generous Commuter Allowance
- In-Office Lunch (5 days per week)
About the Company
- Suno is building the world's first creative entertainment platform, enabling everyone to create music.
- The company is the fastest-growing consumer entertainment company and a leader in AI music.
- Suno is backed by prominent investors including Bond Capital, Menlo Ventures, Lightspeed Venture Partners, IVP, Forerunner, Union Square Ventures, Alkeon, Quiet, Matrix Partners, Schroders Capital, and NVentures (venture arm of NVIDIA).
Equal Opportunity
- Suno is proud to be an Equal Opportunity Employer.
- We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances.
- We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the Massachusetts Fair Chance in Employment Act, NYC Fair Chance Act, LA City Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.
