> Markdown version of [/jobs/ext/1483431-appsec-security-engineer](https://www.wearedevelopers.com/jobs/ext/1483431-appsec-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # APPSEC Security Engineer - **Company:** Digital Asset - **Location:** United States - **Experience:** Experienced - **Salary:** $160,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Digital Forensics, Identity and Access Management, Python (Programming Language), Network Security, Log Analysis, Systems Integration, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Software Security, Cyber Threat Analysis, Kubernetes, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Golang, Dynamic Application Security Testing - **Published:** July 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8e6e0afd90602b1a ## About the Role Candidates must presently reside within a commutable distance from our New York City headquarters with the ability to be on-site, in the office on a hybrid basis. * Vulnerability & Threat Management: Proven ability to perform vulnerability assessments and run penetration tests, interpret the results, and prioritize remediation efforts. Experience with threat modeling and threat intelligence is also key. * Cloud Security: Working knowledge of securing Google Cloud (and AWS, Azure). This includes identity and access management (IAM), GKE, and Cloud Armor, logging, and data protection in the cloud. * Scripting and Automation: Proficiency in scripting language (e.g., Python, GoLang, or Bash) to automate security tasks, analyze logs, and develop custom tools. * Kubernetes and Container Hardenin g: Expertise in securing GKE cluster components, including leveraging native features like Pod Security Standards (PSS) enforcement, and Network Policies to control Pod-to-Pod traffic and runtime security observability. * AppSec Security: Integrating security checks (SAST/DAST, dependency scanning, SCA) into CI/CD pipelines, and hardening build infrastructure and workflows. * Strong oral and written communication skills, ideally experience writing technical documentation and specifications. * Some experience with cryptographic keys, KMS, HSMs * 3-7 years of experience in IT and application security. * Bachelor's Degree Cyber Security, Computer Science or related field. * Based in the NY/NJ/CT tri-state area ## Description * As a Security Engineer, you will have the opportunity to shape our security posture in many domains including; application security, vulnerability management, IAM, cloud and network security, incident response, digital forensics, DevSecOps, etc. * Participate in and, in some cases, lead security incident response efforts, including initial containment, investigation, forensic analysis, and post-incident reporting. * Contribute to the secure design and architecture of new and existing systems, ensuring security is integrated from the start (Security by Design). * Participate in fostering a DevSecOps culture in the company * Collaborate with other teams to facilitate adoption of security processes and tooling ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)