Every nation has data. Few can protect it. Fewer still can act on it.
Dream is the sovereign AI and national cyber-defense company for governments.
We help nations secure their most critical systems, connect fragmented information at a national scale, and turn their most sensitive data into decisions, all fully sovereign.
This is more than a job. It's a Dream job, where you'll work at a global scale alongside some of the best AI researchers, cyber operators, and government experts in the world.
The mission only works if the company behind it does. This role keeps Dream running at the scale our work demands. And our work demands a uniquely global scale.
The Dream JobAs a Senior AppSec Engineer, you’ll plan, build, and support efforts to strengthen security across the organization. As part of our Security & Platform organization, you’ll work across the software development lifecycle and the underlying cloud and platform environment.
You’ll own application security throughout the SDLC, including security requirements, threat modeling, secure design reviews, code reviews, application and API security testing, and production hardening. The role combines application security, cloud and platform security, and security automation. You’ll partner closely with Security, Engineering, Platform, DevOps, and IT teams to build secure-by-default systems and reduce risk at scale.
You’ll also define and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance. This is a hands-on engineering role for someone who can move comfortably between architecture and threat modeling, code and API reviews, cloud and identity guardrails, CI/CD security controls, vulnerability remediation, and automation.
The Dream-Maker Responsibilities- Define, track, and report meaningful security metrics, including control coverage, vulnerability trends, remediation timelines, security exceptions, and baseline compliance.
- Own application security across the SDLC, from security requirements and threat modeling through secure design, code reviews, testing, and production hardening.
- Strengthen cloud and platform security by implementing scalable security controls, identity guardrails, and secure-by-default practices.
- Partner closely with Security, Engineering, Platform, DevOps, and IT teams to reduce security risk and improve security practices across the organization.
- Designing controls for multi-account or multi-cloud environments using Terraform, policy-as-code technologies such as OPA or Sentinel, or automated remediation workflows.
- Experience running a Security Champions, bug bounty or responsible disclosure program, or delivering hands-on secure engineering training.
- You'll translate technical risk into clear remediation guidance and influence engineering and leadership stakeholders through strong written and verbal communication.
- 6+ years of relevant experience across security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering, including substantial hands-on security ownership.
- Deep expertise in either application/product security or cloud/platform security, with demonstrated hands-on capability across the other domain.
- Strong programming and automation skills; proficiency in Python is required, with Go or Bash beneficial, together with practical CI/CD and infrastructure-as-code experience.
- Experience embedding security into the SDLC through threat modeling, secure design and code review, application/API testing and CI/CD controls, supported by strong knowledge of OWASP risks and secure design principles.
- Hands-on experience securing at least one major public cloud platform, including IAM, workloads, networks, logging, organization-level guardrails, containers/Kubernetes, and secrets and key management.
- Experience with relevant application and cloud security tooling, such as SAST, DAST, SCA, secrets scanning, CSPM/CNAPP, and cloud-native security services.
- Hands-on experience with Kubernetes admission controls, image and dependency scanning, supply-chain security and CIS benchmarks.
- Familiarity with OWASP ASVS/SAMM, NIST SSDF/CSF, MITRE ATT&CK, SOC 2 or ISO 27001 control environments.
- Experience securing AI-assisted development workflows, enterprise AI tools, agent-based integrations, or MCP-connected systems.
If you think this role doesn't fully match your skills but are eager to grow and break glass ceilings, we’d love to hear from you!
Skills Required
- 6+ years of relevant experience in security engineering, application/product security, cloud/platform security, software engineering, or infrastructure engineering
- Substantial hands-on security ownership
- Deep expertise in application/product security or cloud/platform security, with hands-on capability across the other domain
- Proficiency in Python
- Strong programming and automation skills
- Practical CI/CD and infrastructure-as-code experience
- Experience with threat modeling, secure design, code review, application/API testing, and CI/CD security controls
- Strong knowledge of OWASP risks and secure design principles
- Hands-on experience securing at least one major public cloud platform
- Experience with cloud IAM, workloads, networks, logging, organization-level guardrails, containers/Kubernetes, and secrets and key management
- Experience with application and cloud security tooling, including SAST, DAST, SCA, secrets scanning, CSPM/CNAPP, or cloud-native security services
- Hands-on experience with Kubernetes admission controls, image and dependency scanning, software supply-chain security, and CIS benchmarks
- Familiarity with OWASP ASVS/SAMM, NIST SSDF/CSF, MITRE ATT&CK, SOC 2, or ISO 27001 control environments
- Experience securing AI-assisted development workflows, enterprise AI tools, agent-based integrations, or MCP-connected systems
- Experience with Go or Bash
- Experience designing controls for multi-account or multi-cloud environments using Terraform, OPA, Sentinel, or automated remediation workflows
- Experience running a Security Champions, bug bounty, or responsible disclosure program, or delivering secure engineering training
- Strong written and verbal communication skills
Dream (dreamgroup.com) Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Dream (dreamgroup.com) and has not been reviewed or approved by Dream (dreamgroup.com).
-
Equity Value & Accessibility — Funding and growth stage in a competitive AI/cyber market are framed as enabling competitive cash-and-equity offers, though the company has not disclosed specifics. Candidates are advised to confirm equity structure and eligibility directly given the lack of public detail.
Dream (dreamgroup.com) Insights
What We Do
Dream is a pioneering AI cybersecurity company delivering revolutionary defense through artificial intelligence. Our proprietary AI platform creates a unified security system safeguarding assets against existing and emerging generative cyber threats. Dream's advanced AI automates discovery, calculates risks, performs real-time threat detection, and plans an automated response. With a core focus on the "unknowns," our AI transforms data into clear threat narratives and actionable defense strategies. Dream's AI cybersecurity platform represents a paradigm shift in cyber defense, employing a novel, multi-layered approach across all organizational networks in real-time. At the core of our solution is Dream's proprietary Cyber Language Model, a groundbreaking innovation that provides real-time, contextualized intelligence for comprehensive, actionable insights into any cyber-related query or threat scenario.


.png)





