> Markdown version of [/jobs/ext/1449756-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1449756-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** BINGHAMTOM UNIVERSITY - **Location:** United States - **Contract:** Permanent contract - **Skills:** Cloud Engineering, Cyber Security, Python (Programming Language), Open Source Technology, Software Engineering, Software Vulnerability Management, Scripting, Git, Containerization, Information Technology, Autodesk Autocad, Software Version Control, Golang - **Published:** July 26, 2026 - **Apply:** https://www.themuse.com/jobs/autodesk/application-security-engineer-602c0a?utm_source=uconnect ## About the Role * Foundational understanding of application security and software development practices. * Familiarity with software supply chain security concepts such as open-source risk, dependency management, and SBOMs. * Experience using or supporting Software Composition Analysis (SCA) tools such as Snyk, Dependabot, or similar. * Basic scripting or automation experience in a language such as Python, Golang, or equivalent. * Familiarity with CI/CD pipelines and modern development workflows (e.g., Git-based version control). * Demonstrates strong ownership, curiosity, and willingness to learn in a collaborative environment. Preferred Qualifications * Bachelor's in computer science, Information Security, or equivalent professional experience. * Hands-on experience generating or consuming SBOMs (e.g., SPDX, CycloneDX). * Experience automating security or development workflows using Python or similar scripting languages. * Familiarity with vulnerability management processes and remediation prioritization. * Exposure to cloud-native or containerized environments. * Strong communication skills and comfort working with developers and security stakeholders. ## Description Our team of security experts helps Autodesk design, build, deploy and maintain secure products. We are embedding security in the full spectrum of how we build our products from inception, design, development, testing to how we are running them in the cloud as well as how we are responding to any existing or emerging threats to our products or the building blocks of our products and services. Our job is to be one step ahead of the bad guys and use expertise, technology and other resources to thwart their efforts to compromise our products and the environment in which they operate. Our team keeps a single-minded focus on protecting our customer's data and their investment in our products by strengthening our applications, underlying services and network. As part of this team, you will help strengthen Autodesk's products by improving the security of our software supply chain. You will work closely with product and platform teams to increase visibility into third-party and open-source dependencies, standardize the use of Software Composition Analysis and SBOMs, and integrate supply chain security controls into build and delivery pipelines. Come practice and grow your product security expertise at scale while helping keep Autodesk one step ahead of emerging supply chain threats. Responsibilities * Support Autodesk's software supply chain security program by helping identify, assess, and reduce risk from third-party and open-source dependencies. * Assist with the onboarding, operation, and continuous improvement of Software Composition Analysis (SCA) tools across Autodesk products and services. * Work with engineering teams to generate, review, and maintain Software Bills of Materials (SBOMs) and improve visibility into dependency usage. * Triage and analyze vulnerability findings from SCA tools (e.g., Snyk, Dependabot), validate impact, and partner with product teams on remediation strategies. * Help integrate supply chain security controls into CI/CD pipelines and developer workflows to support secure by default practices. * Develop scripts and automation to support dependency analysis, reporting, and security workflows. * Contribute to documentation, standards, and best practices related to dependency management, open-source usage, and secure software development. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)