Starbucks · 6 hours ago
application security engineer senior
Starbucks is a company that celebrates coffee and connection, and they are seeking a Senior Application Security Engineer. In this role, you will help protect customer experiences by providing hands-on security engineering and consultative guidance to product and engineering teams.
CoffeeFood and BeverageRestaurantsTea
Responsibilities
Own and deliver core AppSec offensive security testing services by executing in-house penetration testing, operating and continuously improving DAST scanning, and providing AppSec oversight for vendor-delivered penetration testing, including compliance-driven testing, to ensure quality, consistency, and risk-based reporting and prioritization
Drive application security outcomes by translating findings into clear, actionable remediation guidance across web, mobile, and API services, and partnering with engineering teams to reduce repeat issues and measurably improve risk posture over time
Partner and influence across the enterprise by mentoring peers, advising engineering leaders, and contributing as an application security SME during security incidents and for vulnerability disclosure reports, ensuring threats are contained and lessons learned translate into stronger controls
Qualification
Required
Bachelor's degree in a relevant field or 5+ years of equivalent experience in cybersecurity engineering related roles
6+ years of experience working in an information technology discipline
6+ years of infrastructure / information security experience
4+ years of experience working with infrastructure as code technologies
Experience deploying, configuring, and troubleshooting cybersecurity tools in enterprise environments
Certifications such as CISSP, CISSM or others focused on cybersecurity, data privacy or information risk management
Advanced knowledge of cybersecurity principles and practices
Experience with technologies such as firewalls, antivirus software, and intrusion detection systems
Experience with security frameworks and compliance requirements
Proficiency in implementing and managing security controls and technologies
Knowledge of network security protocols and concepts
Familiarity with operating systems and network architectures
In-depth understanding of enterprise-level cybersecurity strategies, frameworks, and technologies
Proficiency in conducting security assessments and audits
Ability to develop and implement security policies and procedures
Experience in managing and responding security incidents
Exceptional problem-solving and troubleshooting skills
Excellent communication and collaboration skills, with the ability to work effectively with cross-functional teams and stakeholders
Advanced experience with at least one modern programming language such as Java, Go, Python, Ruby, C++, or C#
Advanced Proficiency interacting with API's and automating tasks using common scripting languages
Preferred
Experience performing offensive application security testing across web, mobile, and APIs, including manual testing techniques and secure design review
Experience building, operating, or scaling DAST scanning capabilities in an enterprise environment
Experience providing AppSec oversight for vendor penetration testing, including scoping, quality review of evidence and reporting, and retest validation
Familiarity with vulnerability disclosure workflows, including triage, validation, and partner communications
Familiarity working in PCI or other compliance-driven environments where pentesting and evidence requirements are time-bound and auditable
Certifications such as OSCP, OSWE, GWAPT, GPEN (or equivalent) are a plus
Benefits
Medical, dental, vision, basic and supplemental life insurance, and other voluntary insurance benefits
Short-term and long-term disability
Paid parental leave
Family expansion reimbursement
Paid vacation from date of hire
Sick time (accrued at 1 hour for every 25 hours worked)
Eight paid holidays
Two personal days per year
Participation in a 401(k) retirement plan with employer match
A discounted company stock program (S.I.P.)
Starbucks equity program (Bean Stock)
Incentivized emergency savings
Financial well-being tools
100% upfront tuition coverage for a first-time bachelor’s degree through Arizona State University’s online program via the Starbucks College Achievement Plan
Student loan management resources
Access to other educational opportunities
Backup care
DACA reimbursement
Company
Starbucks
Starbucks is a restaurant chain that serves handcrafted ready-to-drink beverages, including coffee, tea, juices, and snack food items.
H1B Sponsorship
Starbucks has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (208)
2024 (127)
2023 (130)
2022 (172)
2021 (146)
2020 (149)
Funding
Current Stage
Public CompanyTotal Funding
$2.65BKey Investors
Elliott Management Corp.Pershing Square Capital Management
2025-05-06Post Ipo Debt· $1.75B
2024-07-19Post Ipo Equity
2018-10-10Post Ipo Equity· $900M
Recent News
2026-02-06
Mercury News
2026-02-06
The Motley Fool
2026-02-05
Company data provided by crunchbase