Apollo
Senior Application Security Engineer
About this role
Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world's largest enterprises. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion. Apollo.io provides sales and marketing teams with easy access to verified contact data for over 210 million B2B contacts and 35 million companies worldwide, along with tools to engage and convert these contacts in one unified platform. By helping revenue professionals find the most accurate contact information and automating the outreach process, Apollo.io turns prospects into customers. Apollo raised a series D in 2023 and is backed by top-tier investors, including Sequoia Capital, Bain Capital Ventures, and more, and counts the former President and COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features. This role blends deep code-level application security work with strong cross-functional partnership. It includes application security reviews, threat modeling, AppSec tooling, findings triage and remediation follow-through, external testing intake, and developer enablement. This role is calibrated at the L6 senior-IC level: owning semi-annual or annual goals, solving ambiguous problems with sound judgment, improving operational processes, and driving meaningful cross-team collaboration and influence. Key Responsibilities Secure SDLC, design review, and threat modeling
- Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment.
- Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch.
- Provide practical security architecture guidance to Engineering, Product, and IT teams
- Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems. Vulnerability management and hands-on remediation
- Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs.
- Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities.
- Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom.
- Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities.
Preferred Qualifications
- Experience supporting or leading security reviews for AI-native products, internal agents, or AI-assisted engineering workflows.
- Experience improving secure-by-design practices and AppSec observability in a fast-moving engineering organization
- Experience with security training, developer enablement, or security champions programs
- Relevant security certifications are a plus Example Success Outcomes
- Improve the health and flow of AppSec findings by keeping prioritization, remediation, and verification moving within defined SLAs.
- Complete recurring application reviews or threat models for important systems and features
- Increase engineering adoption of secure patterns, AppSec tooling, and security training
- Reduce manual toil and improve AppSec signal quality through targeted automation and responsible use of AI-assisted workflows. The listed Pay Range reflects the total cash compensation inclusive of annual base salary and annual bonus as applicable. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonus target and annual base salary for the role. This salary range may be inclusive of several career levels at Apollo and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role who are not located in the US may request the annual salary range for their location during the interview process. Additional benefits for this role may include: equity; company bonus or sales commissions/bonuses; 401(k) plan; at least 10 paid holidays per year, flex PTO, and parental leave; employee assistance program and wellbeing benefits; global travel coverage; life/AD&D/STD/LTD insurance; FSA/HSA and medical, dental, and vision benefits. Tier 1 Pay Range (San Francisco, New York City, Seattle) $218,000—$273,000 USD Tier 2 Pay Range (All other US Locations) $190,000—$237,000 USD We are AI Native Apollo.io is an AI-native company built on a culture of continuous improvement. We’re on the front lines of driving productivity for our customers—and we expect the same mindset from our team. If you're energized by finding smarter, faster ways to get things done using AI and automation, you'll thrive here. Why You’ll Love Working at Apollo At Apollo, we’re driven by a shared mission: to help our customers unlock their full revenue potential. That’s why we take extreme ownership of our work, move with focus and urgency, and learn voraciously to stay ahead. We invest deeply in your growth, ensuring you have the resources, support, and autonomy to own your role and make a real impact. Collaboration is at our core—we’re all for one, meaning you’ll have a team across departments ready to help you succeed. We encourage bold ideas and courageous action, giving you the freedom to experiment, take smart risks, and drive big wins. If you’re looking for a place where your work matters, where you can push boundaries, and where your career can thrive—Apollo is the place for you. Learn more here!