> Markdown version of [/jobs/ext/1855877-sr-application-security-testing-engineer](https://www.wearedevelopers.com/jobs/ext/1855877-sr-application-security-testing-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Application Security Testing Engineer - **Company:** 3M - **Location:** Austin, TX, United States - **Experience:** Expert - **Salary:** $164,612.0 - $201,193.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Microsoft Azure, Static Program Analysis, Cyber Security, Github, Open Web Application Security, Secure Coding, Software Engineering, Enterprise Software Applications, Software Security, GWAPT, Information Technology, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 16, 2026 - **Apply:** https://dejobs.org/x/x/CDD10C993C54432A964CCE71733789B1/job/ ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, or technology field (completed and verified prior to start) * Three (3) years of experience in application security or secure software development in a private, public, government or military environment Additional qualifications that could help you succeed even further in this role include: * Experience using common SAST and DAST tools, as well as performing source code analysis to identify and assess application security vulnerabilities * Certifications such as GWAPT, OSCP, or CSSLP are a plus, * Strong hands-on experience in application security testing and validation * Knowledge of OWASP Top 10, secure coding patterns, and threat modeling * Experience with modern development stacks and CI/CD pipelines * Strong analytical, communication, and documentation skills * Ability to collaborate effectively across application, development, engineering and security teams ## Description As a Sr. Application Security Testing Engineer, you will serve as a technical expert responsible for identifying, validating, and reducing application security risk across 3M's application ecosystem. You will work directly with application and development teams to embed security into design and delivery processes while strengthening enterprise application security capabilities., Management * Act as a subject matter expert supporting application security testing program execution. * Contribute to application security standards and playbooks. * Support planning and prioritization of application security testing activities. Technical * Perform application security testing including SAST, DAST, SCA, and manual validation. * Conduct threat modeling and secure design reviews for new and existing applications. * Validate findings and work with developers to drive effective remediation. * Integrate security tooling into CI/CD pipelines using platforms such as GitHub and Azure DevOps. Organizational * Partner with application, development, platform, and cloud teams to embed secure coding practices. * Provide clear technical documentation and risk summaries for stakeholders. * Support audits, penetration testing coordination, and compliance evidence collection. * Contribute to security awareness and secure development training initiatives., All US-based 3M full time employees will need to sign an employee agreement as a condition of employment with 3M. This agreement lays out key terms on using 3M Confidential Information and Trade Secrets. It also has provisions discussing conflicts of interest and how inventions are assigned. Employees that are Job Grade 7 or equivalent and above may also have obligations to not compete against 3M or solicit its employees or customers, both during their employment, and for a period after they leave 3M. Learn more about 3M's creative solutions to the world's problems at www.3M.com or on Instagram, Facebook, and LinkedIn @3M. Responsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties. Safety is a core value at 3M. All employees are expected to contribute to a strong Environmental Health and Safety (EHS) culture by following safety policies, identifying hazards, and engaging in continuous improvement. ## Related Videos - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)