Application Security Engineer

Peterson Technology Partners Ptp
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 160K

Job location

Remote

Tech stack

Kubernetes Security
API
Agile Methodologies
Artificial Intelligence
Amazon Web Services (AWS)
Software System Penetration Testing
Software as a Service
Cloud Computing Security
Computer Security
Custom Software
DevOps
Digital Forensics
Cryptographic Protocols
Github
Microsoft Software
OAuth
OpenID
Open Web Application Security
Public Key Infrastructure
Systems Development Life Cycle
JSON Web Token
Salesforce
Secure Coding
SonarQube
Systems Integration
Software Vulnerability Management
GaBi Software
Software Security
Mitre Att&ck
Informatica Cloud
Multi-Cloud
HybridCloud
GWAPT
AI Platforms
Information Technology
Bitbucket
TeamCity
Devsecops
Cisco networks
Guidewire
Bamboo
Service Stack
Static Application Security Testing
Databricks
Vulnerability Analysis
Dynamic Application Security Testing

Job description

Our client is looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape their strategy, and partner closely with engineering teams to safeguard our applications from the ground up.

The Senior IT Security Engineer designs, implements, and maintains security controls to protect the organization s systems and data. This role leads security monitoring, vulnerability management, and incident response efforts, while embedding security throughout the SDLC and integrating testing capabilities into CI/CD pipelines. The engineer supports secure development practices and conducts application and API penetration testing. Working closely with development, QA, DevOps, and architecture teams, this role strengthens the security posture of missioncritical SaaS and hybrid cloud applications. The Senior Engineer also advises leadership on security strategies, emerging technologies, and alignment with business goals, ensuring innovative, compliant, and effective security solutions.

Essential Tasks/Major Duties

  • Configure, implement, and maintain security systems with a hands-on approach to ensure the integrity, availability and resilience of the organization s IT infrastructure, applications and data.
  • Serve as a subject matter expert for application, API, and integration security across the enterprise. Establish and embed secure development requirements, best practices, patterns, and guardrails (Left Shift) across platforms, technology stacks, and development teams to enhance the overall application and API security posture.
  • Define, design, implement, and continuously improve application security processes, tools, and metrics. Integrate and optimize SAST, SCA, IAST, DAST, and secrets detection tools within CI/CD pipelines, and monitor, track, and report application and API security metrics to leadership.
  • Conduct comprehensive application and API security reviews, vulnerability assessments, and penetration testing, actively configuring and fine-tuning security tools to identify and remediate gaps.
  • Collaborate with cross-functional teams to enforce security best practices and ensure compliance with relevant standards and frameworks (e.g., NIST CSF, NY DFS, MI DIFS, OWASP, HIPAA/HTRUST), configuring security solutions to meet evolving business and regulatory requirements.
  • Lead incident response and digital forensics investigations, providing technical expertise to analyze cyber events and implement effective remediation actions that minimize operational impact.
  • Mentor and guide security team members, sharing knowledge and expertise in application and API security, threat analysis, vulnerability management, cloud security, and cryptography, while fostering a collaborative, learning-driven team culture., To provide a consistent, fair, and flexible experience for all candidates, we use AI-assisted tools to support parts of the interview process. This includes our proprietary AI platform Pete & Gabi, which includes AI recruiter Rebecca.

These AI hiring tools help us:

  • Conduct recorded video interviews
  • Transcribe interviews
  • Summarize candidate responses
  • Generate job-related insights
  • Streamline communication and scheduling

Please note that:

The AI does NOT make hiring decisions; all decisions are made by our human recruiters, hiring managers, or client partners.

The AI does not evaluate facial expressions, emotions, or physical traits; it is used only to support fairness, consistency, and efficiency.

If you prefer a non-AI interview format, we will gladly provide an alternative.

Technical or Case Interviews (Role-Dependent):

When applying for certain tech jobs, you may participate in:

  • A technical interview
  • A coding challenge
  • A case study
  • A client-specific assessment

We will always explain what to expect in advance so you can prepare with confidence.

Human Review & Selection:

Every candidate's profile including interviews, conversations, and assessments is reviewed by experienced recruiters and hiring leaders.

AI insights may assist with organization and evaluation, but final decisions are always human-driven.

Requirements

  • Bachelor s degree or equivalent combination of education and experience.
  • 7+ years of experience in Application and API Security within a DevSecOps environment.
  • Required certifications include at least one CISSP, CSSLP, CCSP, GSEC, CEH, CISM, or CRISC, in addition to platform-specific certifications (AWS, Microsoft, Cisco, etc.) or domain specific certifications (OSWE, OSCP, GWAPT, or GWEB).
  • Experience in Property & Casualty insurance or other regulated industries preferred.
  • Proven experience securing SaaS and custom applications in complex multi-cloud environments, applying security best practices and compliance frameworks.
  • Expert knowledge of secure SDLC principles, application and API security, container security, and secure coding practices. Deep familiarity with OWASP Top 10, OWASP API Security Top 10, and CWE in DevOps environments using TeamCity, Azure Pipelines, GitHub Actions, and Bitbucket Pipelines.
  • Extensive experience automating security scans and integrating SAST, SCA, IAST, DAST, and secrets detection tools into CI/CD pipelines.
  • Proficiency in managing application security tools, including SonarQube, Black Duck, Synopsys Seeker, Snyk, and Wiz Code.
  • Strong understanding of modern authentication and authorization protocols, including OAuth2, OIDC, JWT, and mTLS.
  • Knowledge of cryptographic protocols and standards such as SSL/TLS, SSH, PKI, and emerging quantum-resistant encryption techniques.
  • Solid understanding of security standards and frameworks, including NIST CSF, NY DFS, MI DIFS, HIPAA/HITECH, MITRE ATT&CK, and domain-specific regulatory requirements.
  • In-depth knowledge of common attack vectors and tactics, with a focus on proactive defense and risk mitigation.
  • Proficient in vulnerability assessment and penetration testing tools, capable of identifying, analyzing, and remediating vulnerabilities across applications and systems.
  • Familiarity with enterprise platforms such as Guidewire, Salesforce, Databricks, and SnapLogic is preferred.
  • Skilled in leading team initiatives using project management and Agile methodologies.
  • Excellent communication skills to clearly articulate security risks, policies, and remediation strategies to both technical and non-technical

Benefits & conditions

Salary: $150,000- $160,000 per year (depends on experience level).

Benefits: Medical Insurance, PTO, 401 (k) and more.

About the company

Peterson Technology Partners (PTP) is an Equal Opportunity Employer committed to creating a transparent, inclusive, and human-centered hiring experience. For more than 28 years, PTP has operated as one of the top IT staffing and recruiting firms in the USA built on trust, long-term partnerships, and technical excellence. Based in the Chicago suburb of Park Ridge, IL, our team of more than 500 employees and consultants is dedicated to, For more than 28 years, PTP has focused on putting people first candidates, consultants, employees, and clients. We're committed to a hiring process that is: * Transparent * Compliant * Equitable * Powered by innovative technology that enhances not replaces human judgment Welcome to the future of hiring at Peterson Technology Partners.

Apply for this position