Application Security Engineer (Security Consulting) - Speciality in Golang


Remote US, San Francisco, Seattle

This role accepts applications for work in the locations as noted above. Roles listing 'Remote US' as a location are not currently available in the following states: Colorado, Iowa, and Louisiana.

Company description

Who We Are

The Application Security (AppSec) team is a blend of security engineers and security-focused software engineers helping ensure Twitter builds and maintains secure software. In addition, we conduct security assessments, provide guidance, develop tooling, and advocate and train engineers throughout the systems development lifecycle (SDLC) to ensure security is prioritized at each step of development. Diversity makes us a better organization and team. We value diverse backgrounds, ideas, and experiences.

Job description

What You’ll Do 

As a Security Engineer, you'll join a team of talented security engineers working to reduce risk across the company. You will work on applications written in Go. We work with engineering and product teams to provide security expertise during each phase of the SDLC and take a leadership role in driving security initiatives. We identify recurring classes of security problems, find the root cause, and develop generalized and creative solutions to reduce the occurrence of application vulnerabilities at scale. We strive to advocate and teach security to engineers. Additionally, we assist with third-party security assessments and operate Twitter’s bug bounty program.


Who You Are

The ideal individual has both application security expertise and development experience. They have in-depth knowledge of application security and can identify potential risks in designs, code, or in deployed applications. They should also have experience with threat modeling, security reviews, pen-testing and providing security guidance to development teams. They recognize the importance of building security solutions that scale both technically and organizationally, and adapt to changing business requirements. They enjoy advocating security by writing, giving talks, or hosting educational sessions for developers.


You will meet most (but need not meet all) of the following points:

  • Bachelor’s or advanced Degree in Computer Science or closely related field.

  • 4+ years of relevant experience.

  • Knowledge of Golang, and typical aspects of the Golang ecosystem.

  • Familiarity with microservice architecture and interactions with AWS platform (Boto3/Python).

  • Expertise with web security standards such as CSP, CORS, and emerging web security technologies.

  • Understanding of security challenges in service architectures or large distributed systems.

  • Expertise with browser security controls and web application security best practices.

  • Experience with finding security design flaws and implementation bugs. 

  • Experience building security and process improvement tools. 

  • Experience communicating security concerns and issues to non-technical audiences.

  • Experience building tools and processes to reliably identify security issues and logic flaws across large code bases.

Additional information

We are committed to an inclusive and diverse Twitter. Twitter is an equal opportunity employer. We do not discriminate based on race, ethnicity, color, ancestry, national origin, religion, sex, sexual orientation, gender identity, age, disability, veteran, genetic information, marital status or any other legally protected status.

San Francisco applicants: Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records

Engineering hiring process
Step 1

Once your application is received, a recruiter will reach out pending your qualifications are a match for the role.

Step 2

If your background is a match, you may have 1-2 technical phone interviews or be given the chance to provide a work sample depending on the role.

Step 3

If the phone interviews go well or your work sample is strong, the final step includes interviews with 5-6 people via a video conference call.


Read Twitter's Applicant and Candidate Privacy Policy here.

U.S. Equal Employment Opportunity information (Completion is voluntary)
Voluntary Information
Privacy and data