This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a Staff Application Security Engineer to help us level up Webflow’s secure development practices ranging from secure coding, tooling, and improving procedures.
Job Responsibility:
Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem
Bring security best practices to the software development lifecycle
Work as part of a team to champion security standards while balancing business strategies and requirements
Support Webflow’s security current and future compliance frameworks
Work to find security vulnerabilities through grey-box techniques, and propose solutions at the architecture and code level to mitigate findings
Contribute code and architecture improvements to enable security within Webflow’s application for engineers
Cross-train entry and mid-level application security engineers
Requirements:
BA/BS degree or equivalent experience
7+ years of application security experience, including hands-on software development
Deep expertise in secure software design, secure coding, and modern web application security
Experience leading threat modeling efforts, conducting advanced penetration testing, and managing third-party pentests
Experience designing, implementing, and evolving software supply chain security programs
Experience implementing and improving Secure Development Lifecycle (SDLC) processes at scale
Experience driving multi-quarter application security roadmaps and complex security programs
Experience leading security initiatives within large-scale solutions
Experience using and building security solutions that leverage agentic AI
Experience participating in and leading response efforts for application security incidents
Passionate about security, continuously learning, and able to clearly explain complex security concepts
Nice to have:
Stay curious and open to growth — actively building fluency in emerging technologies like AI to unlock creativity, accelerate progress, and amplify impact
What we offer:
Ownership in what you help build (RSUs)
Comprehensive medical, dental, and vision plans
12 weeks of paid parental leave for all parents and 6+ weeks of additional paid leave for birthing parents
Inclusive care for family planning, menopause, and midlife transitions
Flexible vacation, paid holidays, and a sabbatical program
Access to mental health resources, therapy and coaching
A 401(k) with 100% employer match (up to $6,000/year) in the U.S., and support for retirement savings globally