> Markdown version of [/jobs/ext/1206373-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1206373-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Clear Capital - **Location:** Reno, NV, United States (Remote available) - **Experience:** Expert - **Salary:** $111,000.0 - $144,400.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), PHP (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Application Services, C++ (Programming Language), Databases, Python (Programming Language), Open Web Application Security, Windows PowerShell, Program Design Languages, Ruby, Secure Coding, Software Engineering, Private Cloud Environment, Scripting, Large Language Models, Software Security, GWAPT, Information Technology, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 8, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4b2452b65f79d197 ## About the Role * 4+ years of related experience required. * Bachelor's Degree, ideally in a technically related field (Computer Science, Information Technology, Software Engineering), or equivalent work experience. * Highly technical and analytical, with a background in software development, and scripting (e.g., Java, Python, C++, Ruby, JavaScript, PowerShell, PHP). * Expertise in application security testing, including hands-on experience with Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools. * Proficiency in application security assessments, including threat modeling, vulnerability and penetration testing, API security, OWASP Top Ten mitigation, and securing applications in AWS and private cloud environments. * Relevant certifications such as C\u007CASE, CSSLP, GWAPT, OSCP, or equivalent. * Experience with frameworks such as ISO 27001, NIST, GDPR, CIS, or SOC 2. ## Description The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies such as middle-tier systems and databases. Additionally, the Sr. Application Security Engineer addresses legacy and emerging security issues, and implements repeatable secure development practices to reduce the introduction of program design flaws that may lead to exploitation. As issues are uncovered, the application security engineer communicates with the appropriate technical and leadership teams to ensure a focus on risk mitigation - allowing for business continuity, but without negligent risk. Application Security Engineers are constantly assessing applications for weaknesses and finding resolutions before they can be abused. This position is also responsible for assessing the security of applications for business-to-business initiatives, third-party relationships, outsourced solutions and vendors. The Sr. Application Security Engineer is expected to recommend programmatic controls, and monitor and manage secure development practices to address modern day issues. Application Security Engineers think like attackers, but always act with integrity and do not abuse their privilege. What You Will Work On * Plan and carry out application security testing in all phases of the software development life cycle to identify vulnerabilities in applications and weaknesses in secure coding practices. * Assess discovered vulnerabilities and recommend risk-mitigating solutions, leveraging automation to improve the efficiency of both testing and remediation processes. * Communicate findings, risks, and recommendations to stakeholders, while documenting delivery and implementation progress against defined service-level agreements (SLAs) and business metrics. * Lead AI security initiatives, including threat modeling production LLM stacks for autonomy and prompt injection risks, and auditing third-party models and APIs to secure the software supply chain. * Attend and participate in product and application projects. This includes interacting with business units and technical teams to understand what is coming and how their projects can be more secure from the beginning. * Collaborate with architects and development teams to drive secure design practices, leveraging established security standards, configurations, and frameworks. * Fully define and follow a security review process to ensure an automated and repeatable process is managed. * Regularly monitor the security community for public-facing security issues, as well as to learn new tactics that can be used in testing. * Train developers and junior application security engineers on weaknesses to avoid. * Perform other duties as assigned., * Wherever it Leads, Whatever it TakesĀ® - No matter how remote, complex, or unexpected. Our commitment never wavers. * Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit. * Lift others up - We lead with empathy and strive to improve the lives of those around us. * Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact. * Raise the bar - We don't settle for industry standards, we redefine them. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)