Elementor's Security Team protects a platform that powers over 14% of the internet - millions of websites, apps, and businesses built by our community of creators. We combine classic security engineering with modern automation and AI-driven tooling to stay ahead of a fast-moving threat landscape, and we work hand-in-hand with R&D to build security into the product from day one.
About the Role
As an AppSec Engineer, you'll be the security partner for our R&D teams - reviewing code and architecture, closing the loop on vulnerabilities, and helping developers ship secure features faster. You'll also own our external vulnerability disclosure channels end-to-end, including leading our Bug Bounty program. This role is a great fit if you have a development background, enjoy digging into code, and want to use AI tools and agents to scale security impact across a large, fast-growing platform.
Application Security & Secure SDLC
- Partner with R&D: work directly with developers to identify, triage, and remediate application-level vulnerabilities.
- Review code & architecture: assess security weaknesses and provide clear, actionable, developer-friendly remediation guidance both in the code and architectural levels
- Own the scanning pipeline: run and tune SAST, DAST, and SCA tools across the codebase and CI/CD.
- Shift security left: drive secure coding practices, threat modeling, and security requirements into the development process.
- Review new features: support security reviews for new products, integrations, and third-party dependencies.
Vulnerability Disclosure & Bug Bounty
- Lead the program: own the Bug Bounty program end-to-end - scoping, triage, severity assessment, payouts, and researcher communication.
- Manage vendor integrations: run and integrate vulnerability submission and disclosure platforms including Patchstack, Bugcrowd, Wordfence and Wordpress.
- Triage & resolve: validate inbound vulnerability reports from all channels and drive them to resolution with the relevant teams.
- Improve the process: continuously raise the bar on intake, triage, and SLA handling for vulnerability reports.
Automation & AI Tooling
- Build AI agents: design and build automation workflows and AI agents that cut manual triage work and speed up remediation.
- Use AI daily: leverage AI coding tools (Claude Code, Cursor, etc.) to boost your own productivity - “agentic thinking”.
- Design AI security Architecture: Build a security apparatus to detect and fix AI produced code and workflows.
- Explore automation platforms: evaluate tools like n8n and Zapier for AppSec workflows.
- Connect the stack: build scripts and integrations linking scanning tools, ticketing systems, and vendor platforms.