> Markdown version of [/jobs/ext/2105906-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2105906-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** N2 Services Inc - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Spring Security, Agile Methodology, Amazon Web Services, Apache Tomcat, Applications Architecture, Software System Penetration Testing, User Authentication, Microsoft Azure, Burp Suite, Cloud Computing, Cloud Computing Security, Configuration Management, Cyber Security, Computer Programming, Continuous Integration, Linux, DevOps, Java Platform Enterprise Edition (J2EE), Identity and Access Management, JSON, JQuery, Python (Programming Language), Network Security, Systems Development Life Cycle, Salesforce.Com, Secure Coding, Software Engineering, TCP/IP, Software Vulnerability Management, Web Applications, Pega, Data Logging, Scripting, Google Cloud, ReactJS, Spring-boot, Software Security, Technical Debt, Information Technology, Web Technologies, Dynatrace, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Dynamic Application Security Testing - **Published:** August 18, 2026 - **Apply:** https://www.dice.com/job-detail/c8f09deb-ddc7-48b9-b02f-ea216d9454f7 ## About the Role We are looking for a Senior Application Security Engineer with strong hands-on experience in software development, application security, cloud security, and DevSecOps. The ideal candidate will work closely with development, cybersecurity, DevOps, and business teams to identify, prioritize, and remediate application security risks. The candidate should be comfortable working across the full software development lifecycle and have practical coding experience. This role requires someone who can understand developers'' challenges while applying strong cybersecurity and risk-management principles., * Bachelor''s Degree Required * 6+ years of IT experience * 4+ years of software development experience * Strong hands-on application security experience * SAST, DAST, SCA * Vulnerability assessment and remediation * Secure coding * API Security * IAM * Application security architecture * CI/CD security and DevSecOps * AWS, Azure, or Google Cloud Platform * Cloud Security * Security automation and scripting * Software Development Lifecycle (SDLC) * Hands-on programming experience in at least 1-2 programming languages * Web applications and web technologies * Cybersecurity and information security * Troubleshooting and problem-solving * Strong communication and stakeholder management Preferred Skills * Java, JavaScript, Python * Spring Boot / Spring Security * React / jQuery * J2EE * Burp Suite * Penetration Testing * Linux * JSON * Network Security / TCP/IP * Salesforce / Pega * Dynatrace * Apache Tomcat * SBOM / Software Supply Chain Security * Risk Management / Risk Assessment * ISO 27001 * CISSP, CISA, CISM or other security certifications * Cloud Infrastructure * Solution Architecture * Security Compliance * Kanban / Agile * Change and Configuration Management ## Description * Triage and remediate findings from SAST, DAST, SCA, vulnerability assessments, and bug bounty reports * Partner with development teams to implement secure coding practices * Provide guidance on application architecture, API security, IAM, authentication, authorization, and logging * Integrate security testing into CI/CD pipelines * Support DevSecOps, cloud security, and security automation * Identify and address software supply-chain and SBOM risks * Assist teams with technical debt, application upgrades, and vulnerability remediation * Perform or support penetration testing and security assessments * Translate technical security risks into clear, prioritized business actions * Collaborate with engineering, cybersecurity, platform, and business stakeholders * Support cybersecurity risk, compliance, and governance activities ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)