> Markdown version of [/jobs/ext/1150752-security-engineer-application-security-identity](https://www.wearedevelopers.com/jobs/ext/1150752-security-engineer-application-security-identity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Application Security & Identity - **Company:** Real Chemistry - **Location:** Boston, MA, United States (Remote available) - **Experience:** Experienced - **Salary:** $60,000.0 - $80,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Audit Trail, Cloud Computing Security, Information Leak Prevention, DevOps, Github, Identity and Access Management, Key Management, OpenID, Security Assertion Markup Language (SAML), Security Information and Event Management, Data Streaming, Tripwire, Data Logging, Data Classification, Large Language Models, Software Security, Infrastructure as Code (IaC), AI Platforms, Low-code, GXP, Static Application Security Testing - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6b5299d570082e34 ## About the Role * 5+ years (or 3-5+ in high-growth environments) in cloud security, 2 of which should be be focused application security * Hands-on security experience with: * + AWS IAM + SAML / OIDC federation + GitHub security tooling * Experience with threat modeling and coordinating penetration testing * Familiarity with SOC 2, GDPR, and HIPAA-adjacent controls * In-depth understanding of the risk lifecycle, * Experience securing GitHub-based CI/CD pipelines * Experience in AWS native environments * Exposure to regulated industries (GxP, 21 CFR Part 11) * Security certifications (CISSP, CCSP, OSCP, GIAC, etc.) * Associates degree or higher * Experience bringing low-code or AI-generated applications under enterprise security controls Pay Range: $60,000-$80,000 This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law, compensation will be determined based on job-related, non-discriminatory factors including but not limited to work experience, skills, certifications, and geographical location. The Company reserves the right to modify this pay range at any time ## Description * Conduct security reviews of Internally developed applications including: * + Data flow validation + Security control design and implementation + Secrets handling + AI/LLM Data Loss Prevention (DLP) * Co-lead production readiness reviews for strictly governed environments: * + Threat modeling + Hardening validation + Compliance mapping (SOC 2and contractual and regulatory requirements) * Define and enforce identity architecture: * + Corporate identity: Entra ID + Workload identity: AWS IAM and GitHub OIDC * Define and manage GitHub native security controls: * + GitHub Advanced Security (CodeQL / SAST) + Dependabot (dependency scanning) + Secret scanning + Branch protection and environment controls * Establish standards for security tooling: * + SAST (CodeQL, Semgrep) + SCA (Dependabot, Snyk) + Container scanning (Trivy, ECR scanning) + Infrastructure as Code (IaC) policy (OPA, Sentinel, tfsec) * Define AWS security standards: * + IAM design and least-privilege access + Logging and audit requirements + Secrets management and rotation * Scope and coordinate third-party penetration testing * Maintain audit logging maturity per environment requirements: * + Baseline logging + User-level activity tracking + Tamper-evident audit trails with SIEM integration * Perform initial triage and risk classification within time requirements for critical issues identified in intake (data exposure, credentials, regulatory risk). * Partner with DevOps Engineering to ensure security policies are implemented in pipelines and infrastructure AI Security & Usage Governance * Define approved AI providers and usage boundaries * Establish prompt data classification and handling policies * Enforce human-in-the-loop requirements where appropriate * Define cost/spend guardrails for AI services ## Related Videos - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)