> Markdown version of [/jobs/ext/1986785-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1986785-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Ironclad, Inc. - **Location:** San Francisco, CA, United States - **Experience:** Experienced - **Salary:** $170,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Computing Platforms, User Authentication, Microsoft Azure, Burp Suite, Software as a Service, Cloud Computing, Configuration Management, Code Review, Cyber Security, Continuous Delivery, Continuous Integration, Data Security, IBM Rational Software, Internet Security, Apache Maven, Open Web Application Security, Prometheus, Secure Coding, Security Software, Software Construction, Software Engineering, TypeScript, Datadog, Google Cloud, Grafana, Sonatype, Software Security, Veracode, Git, Containerization, Kubernetes, Nessus, Checkmarx, Appscan, Terraform, Static Application Security Testing, Vulnerability Analysis, Microservices - **Published:** August 8, 2026 - **Apply:** https://www.careerbuilder.com/job-details/staff-application-security-engineer-san-francisco-ca--4fab402e-3738-4dbd-b462-bc08872c23b2 ## About the Role * Strong proficiency in either Typescript or Javascript. * 3+ Years of experience working in application security or software development, preferably with SaaS companies or in regulated fields. * In-depth knowledge of application security concepts and practices, including OWASP Top 10 and SANS Top 25. * Experience with security testing tools such as Burp Suite, AppScan, and Nessus. * Experience operating in any cloud provider (AWS, GCP, Azure, Digital Ocean etc.). * Ability to appropriately prioritize and respond to different escalations. * Experience working collaboratively with cross-functional teams. * Strong desire to take ownership of problems. * Comfort working in a rapidly evolving environment and dealing with ambiguity. * Excellent communication, analytical and problem-solving skills. * Team and goal-oriented. * High output, low ego. Nice to Have: * AI penetration testing. * Experience with git and software branching and workflow strategies. * Experience working with modern, microservice architectures including in Kubernetes or other containerized environments. * Experience with enterprise observability platforms such as ELK, Datadog, Prometheus, Grafana, etc. * Knowledge of Terraform or other infrastructure-as-code and configuration management solutions. * Experience with SOC 2, ISO 27001, NIST, and CIS standards and frameworks. * Experience with SAST and SCA tools such as Snyk, Checkmarx, Veracode, WhiteSource, or Black Duck., Amazon Web Services (AWS), Analysis Skills, Applications Security, Artificial Intelligence (AI), Associated Press, Authentication, Best Practices, Cloud Computing, Coaching, Code Reviews, Communication Skills, Computer Security, Configuration Management, Continuous Deployment/Delivery, Continuous Integration, Contract Management, Cross-Functional, Cryptography, Establish Priorities, GCP (Good Clinical Practices), IBM Rational AppScan, ISO (International Organization for Standardization), Information/Data Security (InfoSec), Insider List, Internet Security, LinkedIn, Maven, Mentoring, Microservices, Microsoft Windows Azure, Nessus, Penetration Testing, Problem Solving Skills, Process Improvement, Psychiatry and Mental Health, Regulatory Compliance, Risk, Risk Analysis, Risk Management, Sales, Secure Coding, Security Analysis, Security Compliance, Security Software, Software Development, Software Engineering, Software as a Service (SaaS), Standards Development, Technical Leadership, Test Tools, Testing, Threat Modeling, Threat and risk analysis (TRA), Training Program, U.S. National Institute of Standards and Technology (NIST), Vulnerability Scanners, World Health Organization (WHO) ## Description This is a hybrid role. Office attendance is required at least twice a week on Tuesdays and Thursdays for collaboration and connection. There may be additional in-office days for team or company events., Ironclad is seeking an experienced Application Security Engineer with a passion for securing modern software platforms and protecting sensitive data. We are looking for someone with strong experience in automated vulnerability scanning and penetration testing to strengthen our application security program. Whether you are better at building software or better at breaking it, we are interested in hearing from you. We welcome security researchers and strong developers, as well as past security engineers. This role will be responsible for conducting security assessments, identifying and mitigating risks, and implementing security best practices and process improvements across Ironclad's Product, Platform and Engineering teams. Roles & Responsibilities: * Develop and implement secure coding practices, procedures, and standards for software development teams. * Conduct application security assessments and vulnerability testing to identify and mitigate risks. * Perform security reviews of code changes and ensure that security issues are addressed. * Collaborate with cross-functional teams to remediate software vulnerabilities and implement secure coding practices. * Integrate security review processes into Ironclad's CI/CD pipeline. * Conduct threat modeling and risk analysis to protect sensitive data. * Provide domain expertise on protective controls including system, network, encryption, and authentication services. * Work closely with members of the SRE, Development, IT, and Security teams to drive impactful changes to Ironclad's cybersecurity posture. * Work closely with the risk and governance teams to implement compliance and security requirements. * Contribute to secure coding and other cybersecurity training programs. * Stay up-to-date with the latest security trends, vulnerabilities, and attack techniques. * Provide technical leadership and mentorship to other members of the engineering and security teams. ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Stop Committing Your Secrets - GIt Hooks To The Rescue!](https://www.wearedevelopers.com/videos/573-stop-committing-your-secrets-git-hooks-to-the-rescue) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools)