Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+37 more
Job description
- Triage and remediate findings from SAST, DAST, SCA, vulnerability assessments, and bug bounty reports
- Partner with development teams to implement secure coding practices
- Provide guidance on application architecture, API security, IAM, authentication, authorization, and logging
- Integrate security testing into CI/CD pipelines
- Support DevSecOps, cloud security, and security automation
- Identify and address software supply-chain and SBOM risks
- Assist teams with technical debt, application upgrades, and vulnerability remediation
- Perform or support penetration testing and security assessments
- Translate technical security risks into clear, prioritized business actions
- Collaborate with engineering, cybersecurity, platform, and business stakeholders
- Support cybersecurity risk, compliance, and governance activities
Requirements
We are looking for a Senior Application Security Engineer with strong hands-on experience in software development, application security, cloud security, and DevSecOps. The ideal candidate will work closely with development, cybersecurity, DevOps, and business teams to identify, prioritize, and remediate application security risks.
The candidate should be comfortable working across the full software development lifecycle and have practical coding experience. This role requires someone who can understand developers’’ challenges while applying strong cybersecurity and risk-management principles., * Bachelor’’s Degree Required
- 6+ years of IT experience
- 4+ years of software development experience
- Strong hands-on application security experience
- SAST, DAST, SCA
- Vulnerability assessment and remediation
- Secure coding
- API Security
- IAM
- Application security architecture
- CI/CD security and DevSecOps
- AWS, Azure, or Google Cloud Platform
- Cloud Security
- Security automation and scripting
- Software Development Lifecycle (SDLC)
- Hands-on programming experience in at least 1-2 programming languages
- Web applications and web technologies
- Cybersecurity and information security
- Troubleshooting and problem-solving
- Strong communication and stakeholder management
Preferred Skills
- Java, JavaScript, Python
- Spring Boot / Spring Security
- React / jQuery
- J2EE
- Burp Suite
- Penetration Testing
- Linux
- JSON
- Network Security / TCP/IP
- Salesforce / Pega
- Dynatrace
- Apache Tomcat
- SBOM / Software Supply Chain Security
- Risk Management / Risk Assessment
- ISO 27001
- CISSP, CISA, CISM or other security certifications
- Cloud Infrastructure
- Solution Architecture
- Security Compliance
- Kanban / Agile
- Change and Configuration Management
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Is Software Engineering Over-Saturated?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The 8 Best Code Testing Tools
Best Countries for Software Engineers