Application Security Engineer

AgileEngine, LLC
San Francisco, CA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Java (Programming Language) Artificial Intelligence Continuous Integration Python (Programming Language) Systems Development Life Cycle Secure Coding Software Engineering Scripting Large Language Models Software Security Devsecops Security Orchestration, Automation & Response
+2 more
Static Application Security Testing Dynamic Application Security Testing

Job description

We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program. You will work in Python and Java to deploy and tune SAST, DAST, and SCA tools, provide code-level remediation guidance to development teams, and operate with full autonomy building automated security runbooks. The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus.

WHAT YOU WILL DO

  • Engineer and deploy AI-enabled secure code scanning capabilities and “Golden Images” to drive secure-from-the-start adoption;

  • Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows;

  • Architect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise;

  • Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance.

Requirements

If you’re looking for a place to grow, make an impact, and work with people who care, we’d love to meet you!, You must be authorized to work for ANY employer in the US (e.g., s, TN visa holders, U4U with EAD), as we are unable to sponsor or take over employment visa sponsorship at this time;

  • 6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps;

  • Strong coding and architectural proficiency in Python (for security automation and scripting) and/or Java (to confidently read, review, and secure enterprise source code);

  • Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST, DAST, SCA) and integrating them into complex CI/CD orchestration ecosystems;

  • Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks;

  • Upper-intermediate English level.

NICE TO HAVES

  • Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation;

  • Advanced application threat modeling experience.

Benefits & conditions

Competitive compensation: USD-based pay with education, fitness, and team activity budgets.

  • Exciting projects: Modern solutions with Fortune 500 and top product companies.

About the company

AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · WWC 2021

Videos

See all

Related articles

See all