> Markdown version of [/jobs/ext/1728618-lead-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1728618-lead-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Application Security Engineer - **Company:** Seek Careers - **Location:** Detroit, MI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, User Authentication, Cyber Security, Continuous Integration, Secure Coding, Enterprise Software Applications, Software Security, Information Technology, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a839dd1b59b344ce ## About the Role * Bachelor's degree in computer science, Information Technology, Engineering, or a related technical field, or equivalent practical experience. * Minimum of five (5) to seven (7) years of professional experience in information technology, with at least three (3) years focused on application security or closely related cybersecurity work. * Experience applying application security principles, including secure coding, authentication, authorization, and data protection, in production software environments. * Experience leading or significantly influencing application security architecture decisions. * Experience integrating application security practices into modern software development methodologies, including Agile and CI/CD workflows. Preferred Qualifications: * Experience leading or governing enterprise application security or DevSecOps initiatives. * Experience defining standards and operating models for application security tooling (e.g., SAST, DAST, IAST, SCA). * Ability to influence cross-functional teams without direct authority. * Security-related certifications (e.g., CISSP, GIAC, CSSLP, OSCP) are a plus. ## Description The Lead Application Security Engineer provides enterprise-level technical leadership and strategic direction for application security across the organization. This role is a senior individual contributor responsible for defining, governing, and evolving application security architecture, standards, tooling, and DevSecOps practices to ensure security is built into applications by design. This role does not include direct people management but serves as a technical leader, mentor, and escalation point for complex application security initiatives., * Define, own, and govern application security architecture standards, patterns, and requirements across development teams. * Provide senior-level technical leadership, including review and approval of designs for complex, high-risk, or business-critical applications. * Lead or co-own the design, implementation, and ongoing maturity of the enterprise DevSecOps program. * Evaluate, select, and govern application security tooling, including defining usage standards, coverage expectations, and success metrics. * Perform advanced threat modeling and security architecture reviews for externally exposed or high-impact applications. * Act as the primary application security subject matter expert for development and platform teams. * Define, track, and report application security metrics and KPIs to assess program effectiveness and inform leadership. * Serve as a technical mentor and final escalation point for complex application security issues. * Partner with Governance, Risk, and Compliance teams to support secure development training and awareness initiatives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)