Back to board
Early applicant
Suno·SaaS·3 hours ago

Senior / Staff Application Security Engineer

Boston, United States of AmericaOn-siteFull-timeSenior · 6+ years₹1.9Cr – ₹2.7Cr/yrH1B likely

About this role

About Suno

We're building the world's first creative entertainment platform, where the entire world can feel the joy and fulfillment of making music. Music is for everyone: Our users include everyone from grandmothers creating songs for their loved ones, to Grammy winners using Suno Studio, our power tool, to make the most popular hits in the world.

Building the future of entertainment requires ambition. The pace is fast, the problems are hard, and the work demands ownership and intensity. For the right people, it’s incredibly rewarding: a chance to shape a new medium, work with a small team that cares deeply about quality, make music, drink too much coffee, and build something that millions of people use to express themselves in ways that were never before possible.

Suno is the fastest growing consumer entertainment company and the leader in AI music. We are backed by leading investors including Bond Capital, Menlo Ventures, Lightspeed Venture Partners, IVP, Forerunner, Union Square Ventures, Alkeon, Quiet, Matrix Partners, Schroders Capital and, NVentures (venture arm of NVIDIA).

About the Role

We’re looking for a Senior / Staff Application Security Engineer to own the security of how our product is built. You’ll be the person who makes sure our code, APIs, and services are secure by design — threat-modeling the product, hardening the application layer, and building the AppSec practice from the ground up.

What You’ll Do

  • Execute application security end to end: threat-model features and services, and drive remediation of the most significant risks.

  • Secure the application layer against the vulnerabilities that matter most — injection, broken authentication and authorization, and insecure APIs.

  • Build and run a secure SDLC: code-review guardrails, SAST/DAST, dependency and supply-chain security, secrets management, and pre-production testing.

  • Harden authentication, authorization, and session/identity handling across the product.

  • Secure the AI-specific application surface — model and inference endpoints, prompt and input handling, and the new classes of vulnerability that come with shipping generative features.

  • Partner with product and platform engineering to design security in early and raise the security bar across the codebase.

  • Set the standard for how engineering reasons about and ships secure code.


What You’ll Need

  • 6+ years in security engineering with deep, hands-on application-security expertise.

  • Strong command of the vulnerability classes that cause incidents and how to eliminate them at the source — code, API, and authz design.

  • A builder who has stood up AppSec practices and secure-SDLC tooling, not only operated established ones.

  • Fluent in modern application stacks and comfortable in AWS.

  • Able to work shoulder-to-shoulder with engineers and raise the bar without becoming a blocker.

  • Able to write and ship production-quality code, not only review it.

  • Curiosity about emerging AI/LLM threat classes and how to defend against them as the product evolves.

  • Nice to have: Consumer product at scale, secure-by-design work on generative-AI or ML product surfaces, and/or early security-hire experience.


Perks & Benefits for Full-Time Employees

  • Company Equity Package

  • 401(k) with 3% Employer Match & Roth 401(k)

  • Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options)

  • 11 Paid Holidays + Unlimited PTO & Sick Time

  • 16 Weeks of Paid Parental Leave

  • Creative Education Stipend

  • Generous Commuter Allowance

  • In-Office Lunch (5 days per week)

Additional Notes:

  • Applicants must be eligible to work in the US.

  • This role requires working onsite at one of our three offices.

Compensation:

  • $230,000 to 330,000

Suno is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the Massachusetts Fair Chance in Employment Act, NYC Fair Chance Act, LA City Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.