--- title: 'Application Security Engineer at Sequoia' canonical: 'https://feeny.ai/job/application-security-engineer-sequoia-tempe-a4hayjydyz4s' type: 'job' last_seen: '2026-09-06' --- # Application Security Engineer at Sequoia - **Company:** Sequoia - **Location:** Tempe, AZ - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-06-10 - **Last confirmed live:** 2026-09-06 - **Apply:** https://jobs.ashbyhq.com/sequoia/d4ce8c14-ff6a-4bf6-8e34-b1d0f630c14e ## Job description Who We Are: Sequoia is the strategic partner helping investor-backed companies of all sizes achieve their business goals through smarter people spend. For 24 years, we’ve guided the most innovative employers to navigate growth and get the most out of their global people investment. With our expert advisory team and integrated platform, we help clients drive business impact through their total comp and benefits, improving executive decision making, controlling costs, protecting the business, and elevating the employee experience. Visit Sequoia.com http://Sequoia.com or follow us on LinkedIn https://www.linkedin.com/company/sequoia-tpi/%22%20/t%20%22_blank to learn more. As an Application Security Engineer, you will be providing application security expertise throughout the Software Development LifeCycle (SDLC) as well as being responsible for managing and driving forward the Application Security Analytics practices. A key part of your role will also involve validating and testing web applications in order to ensure applications meet the requirements of the SDLC Policy and industry best practices. In addition, undertaking threat modelling and conducting periodic penetration testing using best of breed tools, a good understanding of the OWASP Top 10 vulnerabilities and maintaining documentation. You'll perform various day-to-day activities related to ensuring the security of Sequoias application environment. These tasks may include conducting application security reviews to identify vulnerabilities in software applications that could be exploited by attackers, performing penetration testing to assess the effectiveness of existing security controls and identify potential weaknesses, providing training and outreach to internal development teams to improve their understanding of security best practices, developing security guidance documentation to help others understand how to implement secure systems and applications, developing security tools to automate or streamline security processes, delivering security metrics to stakeholders and working on improving the overall security posture of your organization. What You Get to Do: - Application security reviews - Mobile security reviews - Secure architecture design - Threat modeling - Projects and research work as needed - Security training and outreach to internal development teams - Security guidance documentation - Security tool development - Security metrics delivery and improvements - Assistance with recruiting activities and administrative work What You Bring: -  5+ years' experience with emphasis on application development, application security or related fields. -  3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object-oriented language experience -  2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience -  3+ years' experience in application security technologies with knowledge of application security threats. Experience with threat modeling, attack surface analysis, penetration testing, software vulnerability assessments, and understanding of software security threat vectors. -  Knowledge of Component Analysis using tools such as OWASP Dependency-Check, Bytesafe Dependency Checker, Patton, PHP Security Checker, etc. -  Experience with static and dynamic application security testing. -  Experience with AWS products and services -  Bachelor's degree in computer science or equivalent  Preferences: -  Experience as an application security engineer using a suite of tools used for the following: -  Recon and Information Gathering (e.g. Nmap, NetCat, Spiders, OWASP Zed Attack Proxy). -  Mapping and Discovery (e.g. Burp Suite with plug-ins) -  Exploitation of top OWASP vulnerabilities such as SQL Injection, Cross-site Scripting (XSS), Cross-Site Request Forgery (CSRF) attacks, etc. Experience with tools such as MetaSploit, AppScan or WebInspect. -  Knowledge of Threat modeling using PASTA and STRIDE methodology. -  Knowledge of OWASP Best practices -  Knowledge of OWASP Testing Guide 4.0 -  Knowledge of OWASP Code Review 2.0 -  Knowledge of Software Component Verification Sequoia’s Culture – Our most important asset - Integrity - Passion for service - Innovative - Growth oriented - Caring for others - Promise-centric - Focused on relationship building Sequoia provides equal opportunity to all applicants without regard to race, color, creed, religion, citizenship, national origin, age, sex, sexual orientation, gender identity, pregnancy, marital status, military or veteran status, disability, or any other basis prohibited by applicable law. ## Compensation & Benefits Sequoia provides competitive compensation including base salary, performance-based bonus programs, and comprehensive benefits package. Sequoia’s Candidate Privacy Policy https://www.sequoia.com/legal/candidate-privacy-policy/ ## About Sequoia ## Company Overview - **One-liner**: Sequoia is an integrated platform and advisory firm that helps investor‑backed companies optimize their total compensation and benefits spend. - **Entity Type**: Private (Privately Held) - **Headquarters**: San Mateo, California, United States - **Founded**: 2001 - **Founders**: Greg Golub ## Core Business - Primary industry: Total Compensation & Benefits solutions (Business Consulting and Services, HR Technology) - Target customers: Investor‑backed companies of all sizes (startups to large enterprises), B2B - Mission statement: *“To come through for people who put their trust in us.”* (sequoia.com/company/about) ## Products & Services - **Sequoia OS™** – Integrated platform that unifies compensation, benefits, and risk management. - **Advisory & Brokerage** – Expert strategic guidance on comp, benefits, and risk tailored to each client’s growth stage. - **Outsourcing & PEO** – Co‑employment and HR outsourcing to ease administrative burden. - **Investor Solutions** – Services designed to help investor‑backed companies meet compliance, budgeting, and reporting requirements. ## Market Standing - **Valuation**: Not publicly available (private company) - **Key Metric**: Annual Revenue – USD 140 M (LinkedIn data) - **Notable Clients/Partners**: Over 2,500 clients across 140+ countries; NPS of 75 (sequoia.com) - **Growth Signals**: - Headcount growth of 10.2% YoY (1,049 employees as of mid‑2026) - Geographic expansion to 14 countries (U.S., India, Mexico, Brazil, UK, Singapore, etc.) - Active job postings up 600% month‑over‑month (LinkedIn) ## Competitive Advantages - **Integrated platform + advisory**: Combines technology (Sequoia OS) with dedicated human experts, differentiating from pure‑software or pure‑brokerage competitors. - **Deep specialization**: 24+ years exclusively focused on investor‑backed companies. - **High client satisfaction**: 75 NPS and 2,500+ clients indicate strong retention and trust. ## Strategic Focus - Continue expanding global footprint and platform capabilities. - Deepen relationships with investor‑backed companies across their lifecycle. - Invest in technology to automate and unify people‑spend decisions, while maintaining high‑touch advisory. ## Why Work Here - Culture described as “people‑first”, collaborative, and driven by service. (sequoia.com/company/careers) - Perks: competitive compensation, performance‑based bonuses, best‑in‑class benefits, generous parental & family leave, flexible R&R policies, paid volunteer time off. - Recruiting approach: relationship‑based (direct outreach, networking, referrals) rather than traditional job postings. - Global, distributed team with opportunities in multiple countries. - Engineering and product teams are growing (open roles include Senior Machine Learning Engineer, Lead Backend Engineer, Data Scientist, etc.). ## Sources 1. [sequoia.com](https://www.sequoia.com/) 2. [sequoia.com/company/careers](https://www.sequoia.com/company/careers/) 3. [sequoia.com/company/about](https://www.sequoia.com/company/about/) 4. [linkedin.com/company/sequoia-tpi/jobs](https://www.linkedin.com/company/sequoia-tpi/jobs) ## Other roles at Sequoia - [Reitrement Advisory Operations Manager](https://feeny.ai/job/reitrement-advisory-operations-manager-sequoia-tempe-3stg39f2gp59) — Tempe, AZ - [Payroll Tax Coordinator](https://feeny.ai/job/payroll-tax-coordinator-sequoia-tempe-fccpb36syf6y) — Tempe, AZ - [Senior Visual Designer](https://feeny.ai/job/senior-visual-designer-sequoia-mexico-city-edf04h2x3dqn) — Mexico City, Mexico - [Payroll Specialist](https://feeny.ai/job/payroll-specialist-sequoia-tempe-b543fda4q6wm) — Tempe, AZ - [LOA Program Manager](https://feeny.ai/job/loa-program-manager-sequoia-tempe-v2zw5vhw5j0b) — Tempe, AZ - [Client Analyst](https://feeny.ai/job/client-analyst-sequoia-mexico-city-masxbzt1sbdw) — Mexico City, Mexico - [Senior Software Engineer, Backend](https://feeny.ai/job/senior-software-engineer-backend-sequoia-tempe-14f3hbnsq090) — Tempe, AZ - [Platform Success Manager](https://feeny.ai/job/platform-success-manager-sequoia-tempe-p6tjbqe0yts6) — Tempe, AZ - [Manager, Payroll Services](https://feeny.ai/job/manager-payroll-services-sequoia-tempe-eavem3ws7w0s) — Tempe, AZ - [IT Support Engineer](https://feeny.ai/job/it-support-engineer-sequoia-mexico-city-cshwkxj0r3pa) — Mexico City, Mexico