> Markdown version of [/jobs/ext/1945430-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1945430-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** AgileEngine, LLC - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Continuous Integration, Python (Programming Language), Systems Development Life Cycle, Secure Coding, Software Engineering, Scripting, Large Language Models, Software Security, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 6, 2026 - **Apply:** https://www.dice.com/job-detail/595e005f-160b-4ba7-b100-74b0fdd9c0e6 ## About the Role If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you!, You must be authorized to work for ANY employer in the US (e.g., s, TN visa holders, U4U with EAD), as we are unable to sponsor or take over employment visa sponsorship at this time; - 6+ years of software engineering experience with a strong subsequent focus on Application Security and DevSecOps; - Strong coding and architectural proficiency in Python (for security automation and scripting) and/or Java (to confidently read, review, and secure enterprise source code); - Deep, hands-on expertise deploying and tuning modern application security testing tools (SAST, DAST, SCA) and integrating them into complex CI/CD orchestration ecosystems; - Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks; - Upper-intermediate English level. NICE TO HAVES - Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation; - Advanced application threat modeling experience. ## Description We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program. You will work in Python and Java to deploy and tune SAST, DAST, and SCA tools, provide code-level remediation guidance to development teams, and operate with full autonomy building automated security runbooks. The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus. WHAT YOU WILL DO - Engineer and deploy AI-enabled secure code scanning capabilities and "Golden Images" to drive secure-from-the-start adoption; - Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows; - Architect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise; - Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)