Every nation has data. Few can protect it. Fewer still can act on it.
Dream is the sovereign AI and national cyber-defense company for governments.
We help nations secure their most critical systems, connect fragmented information at a national scale, and turn their most sensitive data into decisions, all fully sovereign.
This is more than a job. It's a Dream job, where you'll work at a global scale alongside some of the best AI researchers, cyber operators, and government experts in the world.
The mission only works if the company behind it does. This role keeps Dream running at the scale our work demands. And our work demands a uniquely global scale.
The Dream Job
As a Senior AppSec Engineer, you’ll plan, build, and support efforts to strengthen security across the organization. As part of our Security & Platform organization, you’ll work across the software development lifecycle and the underlying cloud and platform environment.
You’ll own application security throughout the SDLC, including security requirements, threat modeling, secure design reviews, code reviews, application and API security testing, and production hardening. The role combines application security, cloud and platform security, and security automation. You’ll partner closely with Security, Engineering, Platform, DevOps, and IT teams to build secure-by-default systems and reduce risk at scale.
You’ll also define and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance. This is a hands-on engineering role for someone who can move comfortably between architecture and threat modeling, code and API reviews, cloud and identity guardrails, CI/CD security controls, vulnerability remediation, and automation.
The Dream-Maker Responsibilities
Define, track, and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
Own application security across the SDLC, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
Strengthen cloud and platform security by implementing scalable security controls, identity guardrails, and secure-by-default practices.
Partner closely with Security, Engineering, Platform, DevOps, and IT teams to reduce security risk and improve security practices across the organization.
Designing controls for multi-account or multi-cloud environments using Terraform, policy-as-code technologies such as OPA or Sentinel, or automated remediation workflows.
Experience running a Security Champions, bug bounty or responsible disclosure program, or delivering hands-on secure engineering training.
You'll translate technical risk into clear remediation guidance and influence engineering and leadership stakeholders through strong written and verbal communication.
The Dream Skill Set
6+ years of relevant experience across security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering, including substantial hands-on security ownership.
Deep expertise in either application/product security or cloud/platform security, with demonstrated hands-on capability across the other domain.
Strong programming and automation skills; proficiency in Python is required, with Go or Bash beneficial, together with practical CI/CD and infrastructure-as-code experience.
Experience embedding security into the SDLC through threat modeling, secure design and code review, application/API testing and CI/CD controls, supported by strong knowledge of OWASP risks and secure design principles.
Hands-on experience securing at least one major public cloud platform, including IAM, workloads, networks, logging, organization-level guardrails, containers/Kubernetes, and secrets and key management.
Experience with relevant application and cloud security tooling, such as SAST, DAST, SCA, secrets scanning, CSPM/CNAPP, and cloud-native security services.
Hands-on experience with Kubernetes admission controls, image and dependency scanning, supply-chain security and CIS benchmarks.
Familiarity with OWASP ASVS/SAMM, NIST SSDF/CSF, MITRE ATT&CK, SOC 2 or ISO 27001 control environments.
Experience securing AI-assisted development workflows, enterprise AI tools, agent-based integrations, or MCP-connected systems.
Never Stop Dreaming...
If you think this role doesn't fully match your skills but are eager to grow and break glass ceilings, we’d love to hear from you!