> Markdown version of [/jobs/ext/234878-software-security-engineer](https://www.wearedevelopers.com/jobs/ext/234878-software-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Engineer - **Company:** CELINK, INC. - **Location:** Austin, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $115,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Applications Architecture, User Authentication, Software as a Service, Cloud Computing Security, Static Program Analysis, Code Review, Cyber Security, Continuous Integration, DevOps, Node.Js, Open Web Application Security, Software Engineering, Software Vulnerability Management, Data Logging, ReactJS, Software Security, AngularJS, Information Technology, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d9881ed41c40ed41 ## About the Role Do you have a Bachelor's degree?, * Bachelor's degree (or equivalent experience) in computer science, information security, software engineering, or a related field., * 5+ years of experience in application security, secure software engineering, or a closely related field, with emphasis on enterprise and distributed application environments. * 5+ years of hands-on experience working with software development teams on secure SDLC practices, code review, vulnerability remediation, and security testing; prior software development experience is strongly preferred. Professional Certification/License * Industry certifications such as CSSLP, CISSP or other relevant application security or cloud security credentials are preferred. Skills and Abilities * Strong understanding of modern web, API, and distributed application architectures, and the ability to assess security implications across those environments. * Knowledge of common web, API, and cloud application vulnerabilities and effective remediation approaches, as well as of application security testing tools and methods. * Deep understanding of secure software development principles, including OWASP Top 10 for web and API security, code and dependency analysis, and practical remediation techniques. * Detailed technical knowledge of authentication, authorization, cryptography fundamentals, common application vulnerabilities, and effective remediation strategies. * Practical familiarity with modern application development stacks and frameworks such as React, Angular, Node.js, Java, Javascript. * Ability to influence technical teams, drive remediation, and balance sound risk management with practical delivery needs. * Experience with AWS-hosted applications, CI/CD security integration, and automation of application security workflows. * Ability to articulate, plan, implement, and continuously improve application security practices in partnership with development and technology teams. * Demonstrated strong critical thinking, problem-solving, and analytical ability, including the judgment to prioritize issues based on technical and business risk. * Strong verbal and written communication skills, with the ability to clearly explain security findings and recommendations to developers, architects, and leadership audiences. ## Description We are looking for an experienced and hands-on Application Security Engineer to help secure Celink's internally developed applications, APIs, and support software delivery processes. In this role, you will work closely with engineering, architecture, and DevOps teams to embed secure-by-design practices throughout the software development lifecycle, including requirements review, threat modeling, secure design, code analysis, security testing, and remediation support. You will also help administer and improve application security tooling, define practical security standards for development teams, and provide reporting on application security risks, trends, and remediation progress., * Partner with software engineering, architecture, and DevOps teams to embed security requirements and secure-by-design practices into the software development lifecycle. * Perform threat modeling, secure design reviews, and application architecture assessments for internally developed applications, APIs, and supporting services. * Review results from SAST, DAST, SCA, secrets scanning, and related AppSec tools, and help teams prioritize and remediate findings based on risk and business context. * Help define, document, and improve secure coding standards, development guardrails, and security patterns for internal engineering teams. * Provide guidance and hands-on support to development teams on secure coding practices, common vulnerability patterns, and effective remediation approaches. * Partner with teams to improve application security controls such as authentication, authorization, secrets handling, logging, and secure configuration. * Support and conduct security testing activities for web, API, and cloud-based applications, and validate remediation of identified vulnerabilities. * Configure, maintain, and optimize application security tools and integrations used in CI/CD and developer workflows to improve efficiency, consistency, and coverage of application security processes. * Develop and deliver practical security training and guidance for developers and other stakeholders involved in software delivery. * Support internal audits, risk assessments, and compliance activities related to application security controls and software development practices. * Research emerging application security risks, tools, and techniques, and recommend practical improvements aligned to Celink's environment. * Performs other duties and projects as assigned ## Related Videos - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)