> Markdown version of [/jobs/ext/1907825-builder-minded-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1907825-builder-minded-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # builder-minded Application Security Engineer - **Company:** Cvent - **Location:** United States - **Experience:** Expert - **Salary:** $120,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, JIRA, Microsoft Azure, Bash Shell, Burp Suite, Cloud Computing, Cloud Computing Security, Cloud Engineering, Code Review, Computer Programming, Continuous Integration, Software Design Documents, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Fortify (Software), Secure Coding, Software Engineering, TypeScript, Software Vulnerability Management, AWS Cdk, Google Cloud, Large Language Models, Software Security, Mitre Att&ck, Veracode, Build Management, Machine Learning Operations, Checkmarx, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 3, 2026 - **Apply:** https://www.dice.com/job-detail/4f74d77e-d5ba-4c71-a420-9ed723a5124f ## About the Role * 5+ years of hands-on experience in application security or secure software development, with demonstrated technical ownership. * Strong scripting/programming skills - the ability to design and build non-trivial internal tools and automation in Python, JavaScript/TypeScript, or Bash. * Proven experience integrating security tooling into CI/CD and the SDLC, and improving it over time. * Strong familiarity with cloud platforms (AWS preferred; Google Cloud Platform or Azure acceptable) and cloud-native security, including securing applications built with AWS CDK / IaC. * Proficiency with security testing and cloud security tools (e.g., Burp Suite, Checkmarx, Mend, Veracode, Fortify, ZAP, Wiz) and the judgment to know when manual testing beats automation. * Deep understanding of the OWASP Top 10, CWE, SANS Top 25, secure coding practices, and web/API vulnerability classes. * Demonstrated end-to-end ownership of at least one security tool, automation, or agentic/LLM-integrated workflow that is used in production or relied on by a team - designed, shipped, and depended on by others. This is the primary, screenable differentiator from the Engineer II role. Bonus If You Have: * Experience securing AI/ML pipelines and a working understanding of adversarial ML, prompt injection, and agent-misuse risk. * DevSecOps, IaC security, or supply-chain depth, and senior-relevant certifications (e.g., OSWE, OSCP, AWS Security - Specialty, CISSP). ## Description We're seeking a senior, builder-minded Application Security Engineer who can go deep on hard technical problems while setting the direction for how AI reshapes a security program. This isn't someone who just uses AI tooling - it's someone who architects it: agentic systems that automate threat modeling end to end, AI-assisted vulnerability management, and self-serve security capabilities that change how an engineering org works. The ideal candidate is equally credible doing a rigorous design review, writing the automation that scales it, and communicating the resulting risk decisions to leadership. This role owns product security for the teams it partners with - they look to this person as the accountable security voice for their roadmap. In This Role, You Will: * Architect and own AI-first security automation - design agentic systems and skills that take security work from intake (e.g., a Jira epic or design doc) through analysis to logged risk and published findings, with minimal manual handoff. * Lead the development of security agents and AI tooling - define the architecture for LLM-integrated workflows (via APIs and MCP connectors), set patterns for tool/function design, and decide build-vs-buy across the toolchain. * Drive AI-assisted threat modeling at scale - benchmark custom solutions against off-the-shelf agents, embed methodologies (STRIDE, PASTA, LINDDUN, MITRE ATT&CK) into automation, and make pentest scoping decisions defensible and repeatable. * Set the standard for AI feature security - define coverage models and assessment criteria for GenAI and AI/ML features, applying the OWASP LLM Top 10, OWASP AI Testing Guide, and MITRE ATLAS to real product risk. * Own integration and scaling of SAST, DAST, and SCA across CI/CD, including AI-assisted triage layers that cut noise and accelerate remediation. * Perform and lead deep secure design reviews, code reviews, threat modeling, and penetration testing for complex and high-risk systems, including cloud-native and AI-driven architectures. * Own product security for an assigned product area or portfolio - serve as the accountable security partner for those teams, drive their threat modeling, design reviews, and risk decisions end to end, and own the security posture and remediation outcomes for that scope. * Mentor Engineer II and mid-level teammates, review their automation and findings, and grow the team's AI and AppSec capability. * Communicate risk clearly to both engineering and leadership audiences, and support compliance efforts across ISO 27001, SOC 2, and PCI., * You'll define how AI transforms Application Security at scale - architecting automation and agents that change how an entire engineering org ships secure software. * You'll join the ASRE team to innovate at the forefront of AI-assisted AppSec, with the autonomy to set technical direction. * You'll work with teams who take security seriously and back you to drive meaningful, lasting change. * You'll have both technical depth and leadership impact, with a path to grow into staff-level or lead roles. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Building Reliable Serverless Applications with AWS CDK and Testing](https://www.wearedevelopers.com/videos/812-building-reliable-serverless-applications-with-aws-cdk-and-testing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [The power of Cloud Development Kit (CDK): How to get the most out of it](https://www.wearedevelopers.com/videos/740-the-power-of-cloud-development-kit-cdk-how-to-get-the-most-out-of-it) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)