> Markdown version of [/jobs/ext/1916015-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1916015-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** Citrin Cooperman - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Github, Python (Programming Language), Key Management, Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Secure Coding, Software Engineering, Policy as Code, Scripting, Google Cloud, Cloud Platform System, Software Security, Software Application Programming, Gitlab, Containerization, Kubernetes, Information Technology, Bicep, Terraform, Prisma Cloud Platform, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1668e173c72e31ce ## About the Role * Have a bachelor's degree in computer science, cybersecurity, information security, or related field, or equivalent experience. * Have relevant certifications (e.g., Azure Security Engineer Associate, CKS, GIAC, OSCP). * Have a 5+ years of experience in Application Security, Secure Software Development, DevSecOps, Security Engineering, or a related cybersecurity discipline. * Have hands-on experience securing major cloud environments (AWS, Azure, GCP) and services. * Possess a strong understanding of application security concepts (OWASP Top 10, secure SDLC, threat modeling). * Have experience integrating security tooling into CI/CD pipelines. * Be proficient with at least one scripting or programming language (e.g., Python, PowerShell, Go). * Have familiarity with infrastructure-as-code (Terraform, Bicep, ARM) and containerization (Docker, Kubernetes). * Have a strong security-first mindset. * Be analytical and detail oriented. * Have excellent communication skills. * Be collaborative and accountable. ## Description * Integrate security controls into the developer workflow, including SAST, DAST, SCA, secrets scanning, and IaC scanning. * Partner with development teams to remediate vulnerabilities and provide secure coding guidance and training. * Investigate, prioritize, and drive remediation of application security findings. * Conduct secure code reviews, security assessments, and vulnerability analysis. * Build self-service security tooling and repeatable security design patterns that make the secure path the easy path for developers. * Create and maintain security standards, procedures, and best practices that scale across teams. Cloud Security * Design and implement security controls across Azure workloads, including identity (Entra ID), networking, encryption, and key management. * Configure and manage cloud-native security services. * Establish and enforce cloud security posture standards, compliance baselines, and guardrails using policy-as-code (e.g., Azure Policy). * Monitor, triage, and respond to cloud security findings and misconfigurations. * Deploy, tune, and operate CNAPP tooling (e.g., Wiz, Prisma Cloud, Microsoft Defender for Cloud, Aqua) covering CSPM, CWPP, CIEM, and container/Kubernetes security. * Prioritize and drive remediation of cloud and workload risks based on business context and exploitability. * Build dashboards and reporting to communicate cloud risk to technical and executive stakeholders. * Detect anomalies, investigate alerts, and respond to evolving threats across our cloud ecosystems. * Partner with product and engineering teams to integrate security into application design and development. * Lead threat modeling exercises and identify practical security solutions for complex systems. CI/CD & SDLC Pipeline Security * Embed automated security gates and controls into CI/CD pipelines (e.g., GitHub Actions, Azure DevOps, GitLab, Jenkins). * Work with development team to secure the software supply chain, including artifact signing, dependency management, and SBOM generation. * Harden build environments, pipeline credentials, and deployment processes. * Define and measure security metrics and KPIs across the SDLC. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)