HimalayasHimalayas logo
SmartsheetSM

Senior Security Engineer II, Application Security (Remote Eligible)

The foundation for managing projects, programs, and processes that scale.

Smartsheet

Employee count: 1001-5000

Salary: 175k-245k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

For over 20 years, Smartsheet has helped people and teams achieve–well, anything. From seamless work management to smart, scalable solutions, we’ve always worked with flow. We’re building tools that empower teams to automate the manual, uncover insights, and scale smarter. But more than that, we’re creating space– space to think big, take action, and unlock the kind of work that truly matters. Because when challenge meets purpose, and passion turns into progress, that’s magic at work, and it’s what we show up for everyday.

AI is changing what application security can accomplish. We're not just securing AI; we're using it as a force multiplier to see more risk, act faster, and scale security across a platform used by millions of customers globally. We're looking for a Senior Security Engineer II to join our Application Security team who can do both: bring deep expertise in securing AI-integrated systems, and deploy AI and automation to drive risk visibility and reduction at a scale no traditional security program can match on its own.

This is a high-ownership, technically demanding role for an experienced application security engineer. You will work at the intersection of threat-informed design, engineering automation, and applied AI, doing consequential security work that directly shapes the posture of a modern SaaS platform. If you're a security engineer who writes code to solve security problems, can read a production codebase to find what a scanner misses, and wants your work to matter beyond a ticket queue, we want to talk.

You will report to the Manager, Application Security , based in our Bellevue, WA office, or you may work remotely from anywhere in the US where Smartsheet is a registered employer.

You Will:

  • Secure AI Systems and Use AI to Scale Security: Conduct security reviews and threat modeling of AI-integrated product features (LLM workflows, agentic pipelines, model APIs) with working knowledge of AI-specific risk classes including prompt injection, model manipulation, and runtime control gaps; and in parallel, deploy AI and automation as a force multiplier by building tooling, pipelines, and integrations that extend the team's reach, accelerate triage, and drive risk visibility at a scale manual effort alone cannot achieve.
  • Deliver Application Security Reviews: Own end-to-end security assessments for high-risk features and services (threat modeling, architecture review, targeted code review, and security testing) embedded in the product development lifecycle. Work directly with engineering teams to surface and close risk before it ships, with enough technical credibility to influence design decisions, not just document findings.
  • Advance CI/CD Pipeline Security: Operate and evolve the security scanning controls embedded in Smartsheet's GitLab pipelines (SAST, SCA, secrets, IaC scanning). Tune tools, engage teams on findings, and build automation that reduces false positive burden and improves how developers experience security feedback.
  • Run Bug Bounty Operations: Serve as the expert validation layer for Smartsheet's bug bounty program, reproducing and assessing complex, multi-step researcher submissions requiring authenticated context and deep platform knowledge, making defensible severity and payout decisions, and owning program operations including researcher engagement, metrics, and continuous improvement.

You Have:

  • Experience: 8+ years in application security, with a track record of owning complex, multi-capability work in a product security or AppSec engineering role.
  • Software engineering foundation: Fluent in one or more modern languages (Java, Python, TypeScript/JavaScript, Go, Ruby, or equivalent); you identify security-relevant patterns without relying on tooling and write automation that others adopt.
  • AI security: Hands-on experience securing AI-integrated applications (LLM systems, agentic workflows, model APIs) and demonstrated experience deploying AI and automation to scale security functions or extend team reach. You bring both skill sets.
  • Security review depth: Threat modeling, architecture review, and code review for complex SaaS features; you produce findings engineering teams can act on and carry enough technical credibility to influence design decisions, not just document them.
  • Manual web application testing: Independent, hands-on validation of complex, multi-step authenticated vulnerabilities; you confirm what scanners flag and find what they miss.
  • Bug bounty experience: Operator, active researcher, or both; direct experience with triage, severity calibration, and researcher communication.
  • CI/CD pipeline security: Working knowledge of SAST, SCA, secrets, and IaC scanning in modern pipelines, with experience engaging teams on findings and improving signal quality.
  • Cloud security fundamentals: Working knowledge of AWS, GCP, or Azure sufficient to tie application-layer risk to the infrastructure it runs on; you understand where the application ends and the cloud begins.
  • Legally eligible to work in the U.S. on an ongoing basis
  • BS or MS in Computer Science, a related field, or equivalent industry experience

NICE TO HAVE:

  • Experience with agentic security, MCP security, or adversarial evaluation of autonomous AI systems.
  • GitLab CI/CD experience, including security policy pipeline configuration and scanning job integration.
  • Active bug bounty researcher with published findings, CVE credits, or hall of fame recognition.
  • Penetration testing program management experience: scope definition, vendor coordination, and finding validation with third-party testers.

Current US Perks & Benefits:

  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range
$175,000—$245,000 USD

Get to Know Us:

At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, and India. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 175k-245k USD

Education

Bachelor degree
Postgraduate degree

Experience

8 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About Smartsheet

Learn more about Smartsheet and their company culture.

View company profile

The foundation for managing projects, programs, and processes that scale.

Since our founding in 2005, Smartsheet has enabled individuals and teams to become high achievers. We do this by creating innovative work management solutions, mobilizing a passionate and diverse global team, and making a positive impact in communities where we live and work.

Today, Smartsheet is present in nonprofit organizations, small businesses, and more than 80% of Fortune 500 companies around the globe.

Our game-changing platform is redefining the possibilities of work management and empowering people to do amazing things.

Value-driven culture: Our award-winning culture stems from a core belief that great work experiences have the power to inspire, transform, and move the world forward.

Meaningful impact: We're working with our employees and communities to unlock the power to achieve for everyone and leave a lasting impact on the world.

Investing in employees: We help employees reach their full potential by nurturing a supportive, respectful culture that cares about well-being — both in and outside of the workplace.

Our values drive us

Our values are the beliefs that guide us, and define what we believe is a better way to work:

  • Seizing opportunity: We’re comfortable getting uncomfortable, because we know that if we’re not continuously evolving and improving, we’re falling behind.

  • Winning with integrity: We love to win, but not at all costs. We always strive to act with honesty and transparency, and to do the right thing, even when it’s hard.

  • Prioritizing “We” before “Me”: We work together as one team in service of our mission, and celebrate the big and small successes of each other and our customers along the way.

  • Pursuing progress: We believe deeply that better, fairer, and further is always possible. We work in progress and empower others to do the same—for individuals, for business, and for society.

Employee benefits

Learn about the employee benefits and perks provided at Smartsheet.

View benefits

Paid parental leave

Paid family leave for all parents to support you and your family.

Equity benefits

Eligible employees may participate in our employee stock purchase program (ESPP).

Life insurance

US employees are automatically covered under Smartsheet-sponsored life insurance.

Volunteer opportunities

If you want to volunteer your time to make the world a better place, we’ll pay for that.

View Smartsheet's employee benefits
Claim this profileSmartsheet logoSM

Smartsheet

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

38 remote jobs at Smartsheet

Explore the variety of open remote roles at Smartsheet, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Smartsheet

Remote companies like Smartsheet

Find your next opportunity by exploring profiles of companies that are similar to Smartsheet. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan