> Markdown version of [/jobs/ext/1774446-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1774446-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** AssetMark, Inc. - **Location:** Atlanta, GA, United States - **Experience:** Expert - **Salary:** $130,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software System Penetration Testing, JIRA, Microsoft Azure, Business Software, Software as a Service, Cloud Computing, Cloud Computing Security, Static Program Analysis, Cyber Security, Continuous Integration, DevOps, Dynamic Program Analysis, Github, Information Security Management, Python (Programming Language), Open Web Application Security, Windows PowerShell, Cloud Services, Salesforce.Com, Software Engineering, Systems Integration, Software Vulnerability Management, Data Logging, Software Security, Information Technology, Vulnerability Analysis - **Published:** July 21, 2026 - **Apply:** https://assetmark.wd5.myworkdayjobs.com/AssetMark_Careers/job/Atlanta-GA/Application-Security-Engineer_Req-003899 ## About the Role * Working knowledge of secure software development practices, the OWASP Top 10, threat modeling, API security, and common authentication and authorization patterns * Hands on experience with vulnerability management or application security testing tools, including Rapid7, Arnica, or comparable platforms * Experience assessing and securing enterprise SaaS platforms, including identity, permissions, integrations, logging, and sensitive data protection * Working knowledge of cloud service platforms and CI/CD or DevOps environments, including Azure, GitHub, or comparable technologies * Strong communication and collaborative skills, with demonstrated ability to work directly with development and application owner teams, * 7 to 12 years of experience in application security, product security, SaaS security, cybersecurity, or information technology * BS degree in Cybersecurity, Computer Science, Software Engineering, or equivalent education and experience * Experience securing Salesforce, including profiles, permission sets, connected applications, APIs, integrations, and event monitoring * Hands on experience with static analysis, dynamic analysis, software composition analysis, secrets scanning, and penetration testing tools * Experience with SaaS security posture management, cloud access security broker technologies, or CrowdStrike Falcon Shield * Experience with scripting and automation using PowerShell, Python, APIs, or Infrastructure as Code, and integrating security requirements into JIRA or engineering workflows * Supporting certifications such as CSSLP, CISSP, GIAC, Salesforce, or cloud security certifications ## Description The Application / SaaS Security Engineer is responsible for strengthening the security of internally developed applications and enterprise SaaS platforms across the organization and its product and service lines. This role partners with development, product, platform, and business application teams to assess risk, define security requirements, improve configurations, and support remediation. An ideal candidate combines hands on application security knowledge with practical SaaS security experience and a collaborative, problem solving approach. * Design, enhance, test, and implement application and SaaS security controls across enterprise platforms and internally developed solutions. * Partner with development, product, platform, and SaaS administration teams to integrate security requirements into the software development and application change lifecycles. * Perform threat modeling and security architecture reviews for applications, APIs, integrations, authentication flows, and sensitive data paths. * Conduct scheduled and on demand vulnerability assessments using tools such as Rapid7 and Arnica, and coordinate risk based remediation with technical owners. * Review SaaS security configurations, roles, permissions, integrations, logging, and data protection controls, with emphasis on Salesforce and other critical platforms. * Support application security testing, including static analysis, dynamic analysis, software composition analysis, secrets detection, and penetration testing. * Investigate application and SaaS security incidents and recommend corrective actions to reduce the likelihood of recurrence. * Develop security standards, reusable control patterns, and automated evidence collection for application and SaaS environments. * Perform special projects as assigned, while effectively managing time with competing priorities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)