Full-Time

Staff Application Security Engineer

Infrastructure and Operations Platform

Censys

Censys

51-200 employees

Attack surface management for internet assets

Compensation Overview

$172k - $233k/yr

+ Bonus eligibility + Equity

Remote in USA

Remote

Remote within the United States; in-person onboarding at the Ann Arbor headquarters is expected.

Category
IT & Security (1)
Required Skills
LLM
Bash
Kubernetes
Python
Grafana
GitHub Actions
TensorFlow
PyTorch
Threat modeling
Machine Learning
OpenTelemetry
Infrastructure as Code (IaC)
SOC 2
Prometheus
Terraform
DevOps
Helm
Google Cloud Platform

Get referred to Censys

See people who can refer or advise you

Requirements
  • 10+ years of experience in Security Engineering, DevSecOps, Site Reliability Engineering, or related roles, with a track record of leading security initiatives spanning multiple teams.
  • Deep expertise securing Kubernetes environments, including container images, network policies, and supply chain protections such as Helm and Crossplane.
  • Strong experience with application security tooling, including dependency scanning, static analysis, and policy enforcement, integrated into continuous integration and continuous deployment pipelines such as GitHub Actions and ArgoCD.
  • Strong understanding of attacker tactics, techniques, and procedures and familiarity with frameworks such as MITRE ATT&CK.
  • Strong understanding of cloud services, preferably Google Cloud Platform, especially securing data pipelines, model-hosting endpoints, and related infrastructure.
  • Proficiency with infrastructure as code, including Terraform, Crossplane, or similar tools, and security scanning for cloud resources.
  • Proficiency with scripting and automation, such as Python and Bash.
  • Ability to participate thoughtfully in technical discussions and drive data-driven decisions amid ambiguity and competing priorities.
  • Strong communication skills and empathy for developer needs, with the ability to embed secure practices without creating friction.
Responsibilities
  • Own and drive the application security and DevSecOps program roadmap across engineering, defining the strategy for embedding security into the software development lifecycle through shift-left practices, paved roads, and automation.
  • Design, build, and maintain DevSecOps tooling in Kubernetes and Google Cloud Platform, including support for artificial intelligence and machine learning workloads.
  • Lead the integration of security into continuous integration and continuous deployment pipelines, including code scanning, secret detection, software composition analysis, and infrastructure policy enforcement.
  • Deliver hardened service templates, secure service catalogs, and guardrails that reduce developer cognitive load and organizational risk.
  • Set security architecture direction for artificial intelligence and machine learning workflows by implementing controls for model training, deployment, and inference pipelines, including access control, artifact validation, input and output sanitization, and model provenance tracking.
  • Partner with Corporate Security on company security and compliance initiatives by designing and implementing controls for SOC 2 and ISO 27001 audit readiness and improving tooling for business continuity and disaster recovery, infrastructure policies, and service inventory accuracy.
  • Provide technical leadership and mentorship through design reviews, threat modeling, and pragmatic guidance to engineers across teams.
  • Participate in a shared on-call rotation with the Infrastructure and Site Reliability Engineering teams, supporting production uptime and security incident-response readiness.
Desired Qualifications
  • Experience building or scaling an application security or DevSecOps program from early maturity, including establishing paved roads and measuring adoption.
  • Familiarity with commercial security platforms such as Orca Security and Aikido Security.
  • Experience securing machine learning toolchains such as TensorFlow and PyTorch and familiarity with artificial-intelligence-specific threats including data leakage, model inversion, prompt injection, and adversarial inputs.
  • Hands-on experience integrating and managing web application firewalls, anti-distributed-denial-of-service systems, and edge protection technologies.
  • Familiarity with monitoring and observability systems such as Prometheus, Grafana, and OpenTelemetry, focused on detecting security anomalies.
  • Familiarity with artificial intelligence governance and compliance standards such as the European Union Artificial Intelligence Act and the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework.
  • Interest in using artificial intelligence and large language model tools to improve coding productivity and product capabilities.

Censys offers an attack surface management platform that provides internet intelligence to security teams. The platform continuously scans the internet to discover and inventory internet-facing assets, giving organizations a complete view of their digital exposure. This helps users identify and remediate risks such as open ports, vulnerable software, and misconfigured devices. Customers include Global 2000 companies, government agencies, and security providers, and the service is sold on a subscription basis. Compared with competitors, Censys emphasizes ongoing, wide-scale internet reconnaissance to produce a comprehensive asset inventory and risk context, not just internal scans or point-in-time checks. The company’s goal is to help organizations manage exposure, reduce security risk, and improve threat detection by providing up-to-date visibility into their attack surface.

Company Size

51-200

Company Stage

Debt Financing

Total Funding

$198.1M

Headquarters

Ann Arbor, Michigan

Founded

2017

Get referred to Censys

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • March 31, 2026 funding added $70 million from Morgan Stanley Expansion Capital.
  • First-half 2026 ARR grew 115% in Asia-Pacific and 82% in EMEA.
  • Partner-sourced bookings rose 186% after Tanium and 100-plus integration expansions.

What critics are saying

  • June 2026 rescan delays and risk-instance outages exposed platform reliability weaknesses.
  • Wiz, Palo Alto Cortex Xpanse, and Microsoft Defender EASM pressure Censys on enterprise deals.
  • If Censys becomes a data layer only, margins and pricing power collapse.

What makes Censys unique

  • Censys’ Internet Map tracks domains, IPs, services, certificates, and DNS in one graph.
  • ARC research turns scan data into adversary intelligence and vulnerability advisories.
  • Daily-used dataset powers 300,000 practitioners and over half the Fortune 500.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Company Match

401(k) Retirement Plan

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

-4%

2 year growth

-2%
PR Newswire
Jul 22nd, 2026
Censys reports 400% growth in $1M+ customers as AI threats accelerate demand

Censys, an internet intelligence company, reported record growth in the first half of 2026, driven by enterprise adoption of AI-enabled security workflows. The firm saw 400% growth in customers generating over $1 million in annual recurring revenue and 115% growth in Censys Platform customers. The company expanded internationally, with ARR growing 115% in Asia-Pacific and 82% in EMEA. Censys now operates in 13 countries, serving customers across 46 nations. Partner-sourced bookings grew 186%, with the company surpassing 200 global partners. New strategic partnerships include Tanium, whilst technology partners like Abstract and Swimlane released integrations with Censys. The company enhanced its platform with expanded DNS intelligence, broader protocol coverage, and new AI-native capabilities designed to accelerate security investigations and automate workflows.

PR Newswire
Jul 8th, 2026
Censys adds DNS intelligence to Internet Map for unified threat analysis

Censys has expanded its Internet Map to include real-time DNS visibility, allowing security teams to understand Internet infrastructure through a single platform. The company now integrates domains, DNS records, IPs, hosts, services, and certificates in one unified view. The expansion enables analysts to pivot between name-based and IP-based infrastructure whilst tracking how it evolves over time. Security teams can use the platform across workflows including triage, investigation, threat hunting, and defence. Censys customers have already used the DNS capabilities to identify phishing campaigns. During a recent USPS-themed attack investigation, one malicious domain revealed hundreds of related phishing domains and broader campaign infrastructure, including historical DNS relationships no longer visible through live DNS. The unified platform aims to replace fragmented external intelligence tools with cohesive infrastructure mapping.

PR Newswire
Jun 18th, 2026
Censys expands into security operations with Internet intelligence-powered workflows

Censys, an Internet intelligence platform, has expanded into security operations, enabling organisations to integrate its intelligence across security workflows. The company introduced the Censys Enrichment API, allowing security teams to enrich alerts with real-time Internet context at scale. The expansion builds on recent innovations including risk scoring, adversary intelligence, AI-powered workflows, and integrations with SIEM, SOAR and threat intelligence platforms. Built on the Censys Internet Map, the platform provides continuously updated views of global Internet infrastructure to help security teams validate risks and prioritise responses. Censys customers have used the intelligence to identify emerging threats, including a previously undocumented Russian remote access framework and exposed AI infrastructure. The Ann Arbor-based company serves governments, Fortune 500 companies and security providers globally.

PR Newswire
Jun 4th, 2026
Censys appoints Sandy Dlugozima to lead Southeast US enterprise engagement for SOC modernization

Censys has appointed Sandy Dlugozima as Senior Enterprise Account Executive for the Southeast US to help organisations modernise security operations with real-time Internet intelligence. The company aims to address a critical gap in external context that limits detection, investigation and response capabilities. Security teams modernising their SOCs with AI and automation often have strong internal visibility but lack external context needed to defend against modern threats. This causes AI initiatives to operate on stale, inaccurate data with incomplete external visibility, impacting their ability to deliver expected improvements. Dlugozima will work with customers and partners to integrate Censys' real-time Internet intelligence with SIEM, SOAR and partner-delivered services, providing security teams with a more complete operational view. The company emphasises that without strong external data foundations, automation simply scales incorrect outcomes.

Business Wire
May 29th, 2026
Tanium partners with Censys to unify internal and external exposure management

Tanium has partnered with Censys to deliver a unified approach to exposure management combining internal and external attack surface visibility. The collaboration integrates Tanium's real-time endpoint intelligence with Censys' global internet infrastructure mapping to help organisations identify, prioritise and remediate security risks. The partnership addresses the growing need for continuous exposure management as AI accelerates vulnerability discovery and exploitation. Tanium enables real-time vulnerability scanning and remediation across endpoints, whilst Censys provides visibility into external internet exposures and attacker-controlled assets. The combined solution aims to eliminate silos between internal and external security views, enabling faster risk-prioritised remediation without manual handoffs. Both platforms focus on data quality and real-time intelligence to help security teams move from insight to action more efficiently.