> Markdown version of [/jobs/ext/1465703-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1465703-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Tatari, Inc. - **Location:** New York, United States - **Experience:** Expert - **Salary:** $165,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Software as a Service, Code Review, Cyber Security, Continuous Integration, Python (Programming Language), Open Web Application Security, Secure Coding, Large Language Models, Software Security, Data Pipelines, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/38e53d4f-1c6c-46fc-b8c4-2a5c6f2bace2 ## About the Role * Production Python experience with the engineering depth to review code meaningfully and build security tooling; Java or Rust is a bonus * Significant hands-on application security experience, ideally at a SaaS company, including working knowledge of established standards (OWASP Top 10, API Security Top 10, ASVS, SPVS, AISVS) and how common vulnerability classes manifest in production systems * Threat modeling experience with Product and Engineering teams * Experience building security tooling or automation (scripts, pipelines, libraries) * Familiarity with AWS and Kubernetes security controls as they relate to application-layer risks * Working knowledge of how LLMs introduce new attack surfaces and how to mitigate them, with practical experience using AI tools in security or engineering workflows * Demonstrated experience reviewing API designs and implementations for auth anti-patterns, token mismanagement, injection risks, and sensitive data exposure * Track record embedding with Engineering teams: code review, design consultation, and standards definition * Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch ## Description As our first dedicated Application Security Engineer, you will define the security architecture for everything we ship. You will work directly with our Engineering teams to identify vulnerabilities, design mitigations, and build the tooling and automation that makes secure development the path of least resistance. You will report to the Head of Security as a key technical contributor to Tatari's Security program., * Design and execute greenfield AppSec initiatives across Tatari's SaaS platform from threat modeling to remediation * Build and maintain security automation integrated into CI/CD pipelines and manage software supply chain risk * Own container security across build and runtime * Develop internal tooling and libraries that make secure coding easier for application engineers * Own SAST/DAST/SCA tooling: selection, tuning, CI/CD integration, and triage * Conduct application security reviews and threat models for new features and architectural changes * Identify and remediate vulnerabilities across APIs, services, and data pipelines * Partner with Engineering teams to establish secure coding standards and provide hands-on guidance * Assess and mitigate LLM-introduced risks in product features * Integrate agentic tooling into AppSec workflows to reduce toil * Contribute to security incident response when application-layer issues are involved ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)