> Markdown version of [/jobs/ext/1277552-hiring-for-lead-application-security-engineer-scotttsdale-az](https://www.wearedevelopers.com/jobs/ext/1277552-hiring-for-lead-application-security-engineer-scotttsdale-az). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Hiring For Lead Application Security Engineer @ Scotttsdale, AZ - **Company:** GTN LLC - **Location:** Scottsdale, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $180,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Spring Security, Agile Methodology, Artificial Intelligence, Amazon Web Services, Application Portfolio Management, JIRA, Burp Suite, Cascading Style Sheets (CSS), Cyber Security, Data Validation, Drupal, Junit, Apache Maven, OAuth, Open Web Application Security, Software Maintenance, Mockito, Fortify (Software), Secure Coding, Software Engineering, SQL Databases, Systems Integration, TypeScript, Software Vulnerability Management, Google Cloud, Enterprise Software Applications, GitHub Copilot, Spring-boot, Software Security, Veracode, Git, GWAPT, AngularJS, Information Technology, Rancher, Checkmarx, Restful APIs, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=549a0d36bc93f4e1 ## About the Role * Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience). * 5+ years of Application Security experience, including vulnerability assessment and remediation. * 7+ years of Software Development experience with Java and Angular/AngularJS technologies. * 3+ years of Technical Leadership or Lead Engineering experience. * Strong expertise in Java, Spring Boot, Spring Security, REST APIs, Microservices, JavaScript, TypeScript, Angular, HTML/CSS, SQL, Git, Maven, JUnit, and Mockito. * Hands-on experience with application security tools and methodologies, including SAST, DAST, and SCA. * Deep understanding of OWASP Top 10, secure SDLC practices, and API security. * Experience securing applications using OAuth2, JWT, and modern authentication frameworks. * Strong communication, problem-solving, and stakeholder management skills., * Experience with GitHub Copilot, AI-assisted security tools, AWS, GCP, Rancher, Jira, Drupal, Burp Suite, Checkmarx, or Fortify. * Security certifications such as CSSLP, GWAPT, CEH, or equivalent. * Experience in Agile development environments and enterprise-scale application delivery. ## Description We are seeking a Lead Application Security Engineer to drive secure software development practices while providing hands-on technical leadership across our application portfolio. This role combines deep expertise in Application Security with strong Software Engineering leadership, ensuring that security is embedded throughout the software development lifecycle. The ideal candidate is a highly skilled engineer who can assess and remediate application vulnerabilities, establish secure coding standards, influence architectural decisions, and actively contribute to the design and development of modern applications built on Java, Spring Boot, Angular, and Microservices. This individual will serve as a trusted advisor to both engineering teams and leadership, championing solutions that balance security, performance, scalability, and business objectives., * Lead application security assessments, vulnerability management, and remediation efforts across enterprise applications. * Perform and interpret SAST, DAST, and SCA scans using tools such as Veracode, Checkmarx, Fortify, or equivalent platforms. * Identify, prioritize, and drive remediation of security vulnerabilities, providing guidance on secure coding practices. * Design and implement security controls for REST APIs, including authentication, authorization, input validation, and data protection. * Develop security standards, policies, and best practices aligned with OWASP and industry frameworks. * Produce risk assessments, vulnerability reports, and executive-level security metrics. * Participate in architecture and design reviews to proactively identify and mitigate security risks. * Evaluate AI-generated code and leverage AI-assisted security tools to improve security operations and developer productivity. * Support compliance, audit, and regulatory security requirements. Engineering Leadership * Provide technical leadership for application design, development, and delivery. * Serve as a hands-on contributor, developing and reviewing code across Java, Spring Boot, Angular, and Microservices architectures. * Establish engineering standards that promote high-quality, secure, and maintainable software. * Guide architecture decisions, system integrations, and application modernization initiatives. * Collaborate with stakeholders to translate business requirements into scalable technical solutions. * Mentor and coach development teams on secure coding, software design, and engineering best practices. * Drive continuous improvement in application quality, performance, reliability, and security. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)