> Markdown version of [/jobs/ext/1459150-secure-software-engineer](https://www.wearedevelopers.com/jobs/ext/1459150-secure-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Secure Software Engineer - **Company:** Bright Vision Technologies - **Location:** Tempe, AZ, United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Application Portfolio Management, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Open Source Technology, Open Web Application Security, Software Engineering, Large Language Models, Software Security, GWAPT, Information Technology, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** July 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4634ff632189c1c9 ## About the Role Sponsorship: U.S. Citizens, Green Card Holders, EAD Holders, and H-1B transfer candidates are encouraged to apply. We are unable to sponsor new H-1B visa petitions for this position., * Bachelor's degree in Computer Science, Cybersecurity, or a related field. * Five or more years of application security or security engineering experience. * Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns. * Hands-on experience performing code review across at least two major languages. * Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling. * Strong understanding of authentication, authorization, and cryptographic primitives. * Experience with cloud security and modern infrastructure controls. * Strong communication skills with technical and non-technical audiences. * Proficiency in at least one programming language for tooling and automation. * Experience working closely with engineering teams in an Agile environment., * Industry certifications such as OSCP, OSCE, GWAPT, or CISSP. * Experience with offensive security tooling and red-team operations. * Bug bounty experience, public CVEs, or open-source security contributions. * Familiarity with AI/LLM application security considerations. * Exposure to regulated industries with strict compliance requirements. ## Description We are looking for an Application Security Engineer to embed security throughout the software development lifecycle, partnering with engineering teams to design secure systems, identify vulnerabilities, and reduce risk across our application portfolio. The role blends hands-on offensive and defensive skills with strong communication and collaboration, helping development teams build secure software efficiently rather than slowing them down. The ideal candidate brings deep technical security expertise, strong software engineering fundamentals, and a track record of shipping security improvements that meaningfully reduce risk in production. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)