Elementor Logo
  • Products
    Build with Elementor One
    Everything you need to create, optimize, and manage WordPress sites. Faster, smarter, and all in one place.
    Get Elementor One
    Create
    Build with Editor

    Drag & drop, no code needed

    Generate pages with AI New

    Prompt full pages, design systems, and more

    Use Hello theme

    Apply a lightweight theme to your site

    Launch an online store

    Design and build your WooCommerce store

    Optimize
    Optimize images

    Speed up your site with leaner images

    Improve accessibility

    Scan & fix issues with guided tools and AI

    Boost performance

    Accelerate your website’s speed

    Manage cookie consent

    Customizable cookie banners for GDPR and CCPA

    Manage & Host
    Host your website

    High-speed, secure cloud hosting

    Register a domain

    Get the perfect domain for your brand

    Ensure email delivery

    Reliable sending with built-in tracking

    Manage connected sites

    Monitor and update every site in one place

    Angie Logo
    Build production-ready WordPress assets with Agentic AI, then edit the results with Angie or in the Editor.
  • Agency
  • Enterprise
  • Pricing
  • App Builder
  • Language selector
  • Mobile Buttons
    Log in Get started
Log in Get started
View All Positions

AppSec Architect

  • Full time
  • Senior
  • R&D

Description

Elementor’s Security Team protects a platform that powers over 14% of the internet – millions of websites, apps, and businesses built by our community of creators. We combine classic security engineering with modern automation and AI-driven tooling to stay ahead of a fast-moving threat landscape, and we work hand-in-hand with R&D to build security into the product from day one.

About the Role

As an AppSec Engineer, you’ll be the security partner for our R&D teams – reviewing code and architecture, closing the loop on vulnerabilities, and helping developers ship secure features faster. You’ll also own our external vulnerability disclosure channels end-to-end, including leading our Bug Bounty program. This role is a great fit if you have a development background, enjoy digging into code, and want to use AI tools and agents to scale security impact across a large, fast-growing platform.

Work Environment

Responsibilities

Application Security & Secure SDLC

  • Partner with R&D: work directly with developers to identify, triage, and remediate application-level vulnerabilities.
  • Review code & architecture: assess security weaknesses and provide clear, actionable, developer-friendly remediation guidance both in the code and architectural levels
  • Own the scanning pipeline: run and tune SAST, DAST, and SCA tools across the codebase and CI/CD.
  • Shift security left: drive secure coding practices, threat modeling, and security requirements into the development process.
  • Review new features: support security reviews for new products, integrations, and third-party dependencies.

Vulnerability Disclosure & Bug Bounty

  • Lead the program: own the Bug Bounty program end-to-end – scoping, triage, severity assessment, payouts, and researcher communication.
  • Manage vendor integrations: run and integrate vulnerability submission and disclosure platforms including Patchstack, Bugcrowd, Wordfence and WordPress.
  • Triage & resolve: validate inbound vulnerability reports from all channels and drive them to resolution with the relevant teams.
  • Improve the process: continuously raise the bar on intake, triage, and SLA handling for vulnerability reports.

Automation & AI Tooling

  • Build AI agents: design and build automation workflows and AI agents that cut manual triage work and speed up remediation.
  • Use AI daily: leverage AI coding tools (Claude Code, Cursor, etc.) to boost your own productivity – “agentic thinking”.
  • Design AI security Architecture: Build a security apparatus to detect and fix AI produced code and workflows.
  • Explore automation platforms: evaluate tools like n8n and Zapier for AppSec workflows.
  • Connect the stack: build scripts and integrations linking scanning tools, ticketing systems, and vendor platforms.

Requirements

  • 2-4 years of experience in Application Security, Security Engineering, or Software Development with a strong security focus.
  • Development experience is a clear advantage – a hands-on coding background in any modern language or stack.
  • Solid understanding of common web and application vulnerability classes (e.g., OWASP Top 10).
  • Experience with Application Security Testing tools (such as burp suite, CI/CD pipeline security rule configuration etc)
  • Experience with SAST/DAST/SCA tools and integrating security into CI/CD pipelines.
  • Hands-on, practical familiarity with AI tools and building AI agents for real workflows.
  • Basic coding and scripting skills (Python, Bash, JavaScript, or similar).
  • Strong communication skills and the ability to work closely with developers and cross-functional teams.

Skills & Mindset

  • Ownership mindset – comfortable leading an initiative (like the Bug Bounty program) end-to-end.
  • Ability to work independently, prioritize, and stay calm under pressure.
  • Clear communicator who can translate security findings into practical action for developers and stakeholders.
  • Curiosity for AI tooling and a drive to automate repetitive work.

Nice to Have

  • Prior experience running or participating in a Bug Bounty / responsible disclosure program.
  • Experience with vulnerability disclosure or WAF/plugin security platforms such as Patchstack, Bugcrowd, or Wordfence.
  • Familiarity with n8n, Zapier, or building custom AI agents for security automation.
  • Experience with cloud security fundamentals (AWS, Azure, or GCP)

Podcast

Statement

6

Give it a Shot!

  • FYI

You can choose the additional options
for submitting your candidacy:

  • Contact the Talent Acquisition Team
  • Contact the HRBP
  • Contact the hiring manager
  • Apply for this position below

Build what’s next

Deliver extraordinary websites with the tools trusted by the world’s leading web creators. 30-day money-back guarantee.

Get started
Elementor Logo
WordPress LogoGithub LogoInstagram LogoDiscord LogoFacebook LogoTwitter LogoYouTube LogoTiktok LogoLinkedin Logo

Elementor is a leading website builder for WordPress, powering over 22 million sites and 13% of the web. Built for professionals, creatives, and businesses, Elementor brings design freedom, performance, and control into one seamless creation experience that helps Web Creators build, launch, and manage websites that grow with them.

Get the updates that help you build better.

By entering your email, you agree to our
Terms & Conditions and Privacy Policy.

© Elementor. All rights reserved

Web Creation

  • Website Builder
  • Hello Themes
  • Elementor AI
  • WooCommerce Builder
  • Image Optimization
  • Accessbility
  • Performance
  • Hosting for WordPress
  • Domains
  • Email Deliverability
  • Angie
  • Cookie Consent

Elementor For

  • Agencies
  • Enterprise

Resources

  • Blog
  • Roadmap
  • Developers Website
  • Glossary
  • Free Elementor Download
  • WordPress Download
  • Utilities Center
  • Prompt Library

Company

  • About Us
  • Contact Us
  • Careers
  • FAQs
  • Affiliate Program
  • Trust Center
  • Legal Center
  • Media

Support

  • Help Center
  • Priority Support
  • Services