> Markdown version of [/jobs/ext/1993798-application-security-engineer-ase](https://www.wearedevelopers.com/jobs/ext/1993798-application-security-engineer-ase). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer (ASE) - **Company:** HarbourVest Partners LLC. - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $145,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Business Systems, C Sharp (Programming Language), Software as a Service, Cloud Computing, Software Quality, Cyber Security, Cursor (Graphical User Interface Elements), Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Integration, Web Applications, GitHub Copilot, Software Security, GWAPT, Information Technology, GPT, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 8, 2026 - **Apply:** https://www.dice.com/job-detail/df2072eb-c702-487b-9a77-94c00a3b455e ## About the Role * Dedicated to protecting sensitive financial data, client information, and critical business systems * Skilled in navigating regulated financial services settings * Able to assess and prioritize security concerns by considering their effect on business and financial outcomes * A collaborative partner to engineering, risk, compliance, and audit teams * Proactive, diligent, and calm when responding to security incidents, * Solid understanding of application security principles and OWASP Top 10 risks * Experience securing web applications, APIs, and microservices in financial environments * Hands-on experience with AI-assisted coding tools such as Cursor, GitHub Copilot, and ChatGPT Codex, with an understanding of their security implications in enterprise software development * Proficiency reviewing code in at least one common language (Java, Python, C#, or JavaScript) * Familiarity with cloud platforms, containers, IaaC, and modern DevSecOps tooling * Ability to clearly communicate technical risk to both technical and non-technical collaborators Education Preferred: * Bachelor's degree or equivalent experience in Computer Science, Information Security, or a related field * Security certifications such as CISSP, CSSLP, OSCP, GWAPT, or similar are a plus Experience: * 3-5 years of experience in application security or secure software development * Experience working in controlled sectors such as finance, banking, or fintech * Exposure to compliance frameworks (e.g., SOC 2, SOX, PCI DSS, GDPR) ## Description As a key member of the Security Engineering team, this person will help lead HarbourVest's Application Security program. The Application Security Engineer (ASE) will serve in a multi-functional role, advising development teams on secure coding and accepted industry procedures. The ASE is responsible for leading SDLC initiatives that include secure code reviews, architecture assessments, and application scanning methods. They will provide end-to-end leadership for application security, working closely within platform teams to advocate for and enhance a strong program focused on application security. In this role, they will help uphold and continuously improve HarbourVest's high security standards across infrastructure, applications, and operational processes., * Identify risks and areas of exposure in applications, SDLC processes, and architecture * Define guardrails, standards, and secure usage patterns for agentic AI-based coding tools, enabling engineering teams to adopt them safely while managing data exposure, code quality, and security risk * Perform secure build reviews, threat modeling, and application security testing (SAST, DAST, SCA) * Identify, assess, and support remediation of vulnerabilities in web applications and APIs * Partner with engineering teams to promote secure coding standards utilizing CI/CD pipelines and DevSecOps practices * Support audits, regulatory exams, penetration tests, and security incident response * Secure and continuously monitor third-party SaaS applications using SSPM tools, ensuring configurations, access controls, and integrations meet HarbourVest security standards * Establish metrics and reporting to track coverage and effectiveness of security processes * Enable developers through secure coding guidance, training, and tooling * And other responsibilities as required! ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)