Senior Staff Application Security Engineer
Listed on 2026-01-16
-
IT/Tech
Cybersecurity, AI Engineer
Senior Staff Application Security Engineer
Join Us at Pura—Reimagining Fragrance for the Future
At Pura, we believe life is better when it smells good. Fragrance has the unique power to transform spaces, elevate moods, and create lasting memories. But we know it can do even more. That’s why we’re pioneering the future of fragrance, combining cutting‑edge smart home technology with premium, clean scents to create personalized, meaningful experiences in every home.
We’re not just a fragrance company—we’re on a mission to change the way people experience scent. At Pura, we are redefining fragrance as a critical element of design, on par with color, texture, sound, lighting, and furniture. We call this Scent Design—transforming scent from an afterthought into an intentional, skillful component of every space. By blending artistry and science, Pura allows users to design their own “scents capes” that enhance daily life and craft environments that feel as good as they smell.
WhyJoin Pura?
Our journey began with two innovators, Richie Stapler and Bruno Lima, and their shared vision of revolutionizing how we experience fragrance. Since then, Pura has grown into a company that sells a fragrance every 3.7 seconds, partnering with iconic brands like Curio, Anthropologie, and Disney. We’ve been recognized as the Fastest Growing Company in Utah, and we are passionate about making scent a core part of life’s most memorable moments.
YourRole at Pura:
As a Senior Staff Application Security Engineer, you will be the primary technical authority for our application security program. This is a high-impact leadership role reporting directly to the Director of Security. You will be responsible for securing the entire Pura ecosystem—from our mobile apps and cloud-native backend to our innovative IoT hardware and emerging AI-driven features.
You aren't just finding bugs; you are designing the secure workflows that empower our engineering teams to move fast without breaking our "hard no" policy on security risks. Your role goes beyond simple bug detection; you will architect secure, efficient workflows. This empowers our engineering teams to accelerate development while upholding our commitment to best-in‑class policies, recognizing that they are negotiable to align with business needs.
Compromise is key to creating the best solutions that allow the business to move fast while still ensuring we have mitigating safety features. You will lead manual code audits, architect security for AI/LLM systems, and proactively hunt for threats that target our unique "Scent Design" platform.
* Open to remote/hybrid candidates
You will help us inspire a belief in the power of fragrance to craft and elevate memorable moments for our Owners. This is your chance to make an impact in a high‑growth company that’s redefining the way people experience scent.
What You’ll Own:- Security Architecture & AI Integration:
Lead the design and security review of AI‑powered features, ensuring LLM safety (preventing prompt injection, data leakage, and RAG vulnerabilities). - Secure Workflow Design (Dev Sec Ops ):
Design and implement "secure‑by‑default" guardrails and automated security pipelines (SAST, DAST, SCA) that integrate seamlessly into Git Hub Actions and CI/CD. - Advanced Code Auditing:
Conduct deep‑dive manual source code reviews of complex features, focusing on business logic flaws and authorization issues that automated tools miss. - Threat Hunting & Research:
Lead proactive application‑level threat hunting exercises to identify anomalies and indicators of compromise (IOCs) within the Pura cloud and IoT ecosystem. - Vulnerability Management:
Own the end‑to‑end lifecycle of security findings, from triage and reproduction to partnering with engineering for remediation
Essential Functions:
- Act as a technical mentor and "Security Champion" lead for the engineering organization.
- Perform architectural risk analysis and threat modeling for new product launches.
- Develop custom security tooling and automation scripts to reduce manual toil.
- Stay ahead of the curve on IoT security standards and emerging AI attack vectors.
- Collaborate with the Director of Security to define…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).