Senior / Staff Application Security Engineer

Suno

3h ago 0 views 0 applications
Full-time On-site
Boston
$230,000 - $330,000
Full-time
Security Engineer Application Security

Job Description

Senior/Staff Application Security Engineer - Pioneer AI Music Security at Suno

Imagine a world where anyone can create music. At Suno, we're making that a reality. We're building the planet's first creative entertainment platform, empowering everyone from grandmothers crafting personalized lullabies to Grammy-winning artists producing global hits with Suno Studio. Music is for all, and our technology is unlocking unprecedented avenues for self-expression.

Building the future of entertainment demands relentless ambition, intensity, and deep ownership. The problems are complex, the pace is exhilarating, and the impact is immense. For the right individual, this is a unique chance to shape a new creative medium, collaborate with a tight-knit team passionate about quality, drink copious amounts of coffee, make music, and build something truly transformative that millions will use.

Suno stands as the fastest-growing consumer entertainment company and the undisputed leader in AI music. We are backed by a formidable list of investors, including Bond Capital, Menlo Ventures, Lightspeed Venture Partners, IVP, Forerunner, Union Square Ventures, Alkeon, Quiet, Matrix Partners, Schroders Capital, and NVentures (NVIDIA’s venture arm).

About the Role
We are seeking a visionary Senior or Staff Application Security Engineer to architect and own the security posture of our groundbreaking product. This is a foundational role where you will be instrumental in ensuring our code, APIs, and services are secure by design. You'll spearhead the threat modeling of our innovative features, harden our critical application layers, and establish our AppSec practice from the ground up, with a critical focus on the unique challenges presented by generative AI.

What You’ll Do

Lead End-to-End Application Security: Drive comprehensive threat modeling for new features and services, meticulously identifying and remediating critical risks across the product lifecycle.
Fortify the Application Layer: Defend our application layer against the most impactful vulnerabilities, including advanced injection techniques, broken authentication and authorization mechanisms, and insecure APIs.
Build a Secure SDLC: Design, implement, and run a robust Secure Software Development Lifecycle, integrating code-review guardrails, SAST/DAST tooling, dependency and supply-chain security, secrets management, and rigorous pre-production security testing.
Harden Identity & Access: Strengthen authentication, authorization, and session/identity handling across our entire product ecosystem.
Innovate AI Security: Pioneer defenses for our unique AI/ML application surfaces, including model and inference endpoints, prompt engineering, input handling, and proactively address emerging vulnerabilities inherent to generative features.
Strategic Partnership: Collaborate closely with product and platform engineering teams to embed security early in the design phase and elevate the security bar across our entire codebase.
Champion Security Best Practices: Set the benchmark for how our engineering teams approach and deliver secure code, fostering a strong security culture.

What You’ll Need

Proven Expertise: 6+ years of dedicated, hands-on experience in security engineering with deep, practical application security expertise.
Mastery of Vulnerabilities: Strong command of the vulnerability classes that lead to significant incidents and proven strategies to eliminate them at the source—through robust code, API, and authorization design.
Architect & Builder: A proven track record of *founding* and *scaling* AppSec practices and secure SDLC tooling from inception, not just operating established frameworks.
Modern Tech Fluent: Fluent in modern application stacks and highly proficient in AWS environments.
Collaborative Leader: Able to work shoulder-to-shoulder with engineers, raising the security bar without becoming a blocker to innovation or progress.
Code Proficiency: Capable of writing and shipping production-quality code, beyond just reviewing it.
AI Security Curiosity: A keen curiosity about emerging AI/LLM threat classes and a proactive approach to defending against them as our product evolves.
Nice to Have:

Experience in consumer product development at scale.
Direct secure-by-design work on generative-AI or ML product surfaces.
Early security-hire experience in a rapidly scaling startup environment.

Perks & Benefits for Full-Time Employees

Company Equity Package
401(k) with 3% Employer Match & Roth 401(k)
Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options)
11 Paid Holidays + Unlimited PTO & Sick Time
16 Weeks of Paid Parental Leave
Creative Education Stipend
Generous Commuter Allowance
In-Office Lunch (5 days per week)

Additional Notes:

Applicants must be eligible to work in the US.
This role requires working onsite at one of our three offices.

Compensation:

$230,000 to $330,000

Suno is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the Massachusetts Fair Chance in Employment Act, NYC Fair Chance Act, LA City Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.