> Markdown version of [/jobs/ext/1265437-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1265437-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** American CyberSystems - **Location:** Charlotte, NC, United States (Remote available) - **Experience:** Expert - **Salary:** $170,560.0 - $183,040.0 - **Contract:** Temporary contract - **Skills:** Test Suite, Artificial Intelligence, Continuous Integration, Python (Programming Language), Systems Development Life Cycle, Large Language Models, Software Security, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 14, 2026 - **Apply:** https://www.jofdav.com/jobs/58824967-application-security-engineer ## About the Role * Experience in Application Security (with enablement or CoP experience) * Hands-on in AI/LLM security (prompt injection, RAG, guardrails) * Strong Python automation skills (security testing, adversarial probes) * Expertise in secure SDLC, CI/CD security, and threat modeling * Experience with SAST, DAST, SCA & ServiceNow AVR * Proven ability to mentor developers and influence engineering teams ## Description * Integrate security controls into CI/CD pipelines (SAST, DAST, SCA, AVR flows) * Operationalize AI adversarial testing & define Golden Test Suites * Build security KPIs, dashboards & compliance tracking * Enable teams via training, playbooks, threat modeling & workshops * Act as the bridge between Security & Engineering * Drive governance, risk tracking, and enterprise security standards adoption ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How To Test A Ball of Mud](https://www.wearedevelopers.com/videos/173-how-to-test-a-ball-of-mud) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)