> Markdown version of [/jobs/ext/1918887-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1918887-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Commure Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Static Program Analysis, Code Review, Cyber Security, Information Systems, Data Security, Natural Language Processing, Open Web Application Security, Requirements Management, Secure Coding, Service Pack, Software Engineering, Large Language Models, Software Security, Electronic Medical Records, Information Technology, Data Management, Data Pipelines, Static Application Security Testing - **Published:** August 4, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-application-security-engineer-mountain-view-ca--985bf30e-20c6-48e3-8499-a28751e11bcd ## About the Role * 5+ years of hands-on application security or software engineering experience, not mainly audit or compliance work * Genuine engineering depth: you can read and reason about code well enough to find real bugs and root causes * Strong AppSec fundamentals: threat modeling, secure code review, and OWASP-aligned vulnerability knowledge * Comfort operating independently with good judgment in a fast-moving environment * Clear communication that earns trust with engineers Nice to Have * Experience securing agentic AI or LLM-powered systems * Experience building SAST pipelines or custom static analysis rules * Healthcare or other regulated-industry security experience (PHI, HIPAA) * Offensive security background (bug bounty, CTF, pentesting) * Direct enterprise customer experience, Applications Security, Artificial Intelligence (AI), Automation, Claims Processing, Code Reviews, Communication Skills, Customer Experience, Data Management, Documentation, Enterprise Protection, Establish Priorities, HIPAA (Health Insurance Portability and Accountability Act), Healthcare, Information Technology & Information Systems, Information/Data Security (InfoSec), Machine Tool, Medical Record System, Natural Language Processing (NLP), Operating Systems, Patient Care, Product Programs, Product Reviews, Requirements Management, Risk, Security Design, Software Agents, Software Engineering, Software Patches, Static Analysis, Threat Modeling ## Description Security patterns that worked 20 years ago don't hold up anymore, especially as AI changes how fast engineering teams ship code. We're looking for an Application Security Engineer who combines real engineering depth with security fundamentals - someone who gets into the code, spots systemic patterns, and builds the tooling and fixes that address them at scale, rather than flagging issues for someone else to resolve. This isn't an audit-from-a-distance role. You'll work directly with engineering, with no interim layer needed, and you'll be equally comfortable owning a project end-to-end as you are looping in support when it counts. Full Time position requires working 3 days a week in our Mountain View office (Hybrid) What You'll Do * Identify systemic security gaps in our codebase and engineering workflows, and drive durable fixes with engineering, not just one-off patches * Build security tooling and automation, including SAST/SCA integration and custom checks, that catches issues earlier rather than after they ship * Conduct code reviews and security design reviews for major product initiatives, including agentic AI systems and data pipelines * Drive threat modeling for new features and translate requirements into guidance engineers actually use * Think through what AI-accelerated development means for how we find, prioritize, and fix risk, and use AI tooling where it genuinely helps * Present our security posture to enterprise customers, including healthcare and regulated-data conversations, Employees will act in accordance with the organization's information security policies, to include but not limited to protecting assets from unauthorized access, disclosure, modification, destruction or interference nor execute particular security processes or activities. Employees will report to the information security office any confirmed or potential events or other risks to the organization. Employees will be required to attest to these requirements upon hire and on an annual basis. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [IKEA Story: Transforming an Iconic Retail Brand](https://www.wearedevelopers.com/videos/444-ikea-story-transforming-an-iconic-retail-brand) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)