> Markdown version of [/jobs/ext/1853304-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1853304-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Ensemble Health Partners - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $101,000.0 - $152,400.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), .NET Framework, Agile Methodology, Cyber Security, Computer Programming, DevOps, Issue Tracking Systems, Python (Programming Language), Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Integration, Scripting, Software Security, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 22, 2026 - **Apply:** https://ensemblehp.wd5.myworkdayjobs.com/EnsembleHealthPartnersCareers/job/Remote---Nationwide/Senior-Application-Security-Engineer_R047508 ## About the Role * Deep expertise in application security tooling (SAST, DAST, SCA, IaC scanning, secret scanning) * Strong understanding of secure coding principles and SDLC integration * Proficiency in scripting and programing languages (e.g., .NET, Python, JavaScript) Analytical Skills: * Ability to analyze and validate security findings, prioritize risk, and guide remediation * Strong attention to detail in identifying false positives and systemic security gaps Communication Skills: * Ability to clearly communicate technical issues to both technical and non-technical stakeholders * Skilled in writing documentation, reports, and presenting findings to cross-functional teams Team Collaboration: * Experience working in Agile/DevOps environments with cross-functional teams * Ability to mentor junior engineers and lead small-scale security initiatives * Ability to work effectively with a remotely located team spanning multiple time zones Continuous Learning: * Commitment to staying current with evolving security tools, threats, and best practices * Active pursuit of professional development and relevant certifications, This posting addresses state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role's range. ## Description The Senior Application Security Engineer, Cybersecurity will serve as a key member of the Cybersecurity Technical Assessments team, providing advanced expertise in secure software development practices and application tooling. This role is responsible for managing and optimizing the application security tool stack-including SAST, DAST, SCA, IaC scanning, and secret detection-and ensuring its effective integration into the software development, lifecycle (SDLC). The Senior Application Security Engineer will collaborate with development, engineering, and product teams to identify, triage, and remediate vulnerabilities, while also mentoring junior engineers and contributing to the evolution of secure development practices across the organization., * Manage and optimize application security tools (SAST, DAST, SCA, IaC, secret scanning) and ensure effective integration into CI/CD pipelines and the SDLC lifecycle * Analyze source code and infrastructure-as-code for security vulnerabilities and provide actionable remediation guidance * Validate and triage findings from security tools, removing false positives and ensuring accurate issue tracking * Create and manage remediation tickets (e.g., Aha! Ideas, ServiceNow Requests), ensuring vulnerabilities are prioritized, assigned, and tracked to resolution * Collaborate with development and engineering teams to validate remediation efforts and confirm closure of security issues * Participate in the risk management process by documenting, reviewing, and maintaining risk exceptions for unresolved or accepted vulnerabilities * Work with risk owners and business stakeholders to ensure appropriate compensating controls are in place and documented * Lead secure code reviews and contribute to threat modeling and design discussions for high-risk applications * Mentor junior engineers and provide technical guidance on secure development practices * Contribute to the development and refinement of secure coding standards, policies, and procedures * Develop and maintain dashboards and reports that communicate application security posture, remediation progress, and risk trends to leadership * Identify recurring security issues and propose systemic improvements to reduce future risk * Lead efforts to evaluate, pilot, and implement new application security tools and integrations that enhance automation and coverage * Continuously refine scanning configurations and policies to improve signal-to-noise ratio in findings * Stay informed on emerging threats, vulnerabilities, and industry trends, and recommend improvements to tooling and processes * Participate in the evaluation and onboarding of new security tools and technologies * Work closely with cross-functional stakeholders to analyze and troubleshoot complex production issues ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [React Developer Salary [2023]](https://www.wearedevelopers.com/magazine/198-react-developer-salary-2023)