> Markdown version of [/jobs/ext/2391145-application-security-specialist](https://www.wearedevelopers.com/jobs/ext/2391145-application-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Specialist - **Company:** The Zone - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Server Applications, Software Applications, C++ (Programming Language), Cloud Computing Security, Static Program Analysis, Software Debugging, Dynamic Program Analysis, Python (Programming Language), Reverse Engineering, Software Security, Information Technology, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c4dac3542412ec39 ## About the Role * BSc / MS in computer science or a related field * Previous CVEs in desktop applications * Proficiency with reverse engineering tools * Significant experience in memory exploitation techniques (e.g. gaining code execution from * memory vulnerabilities in modern operating systems) * Familiarity with cloud security best practices * 3+ years of industry experience * OSCP / OSWE / OSED / RET2 certification Will definitely be a plus: * An attacker mindset: engineers will often want proof before fixes are implemented * Eagerness to learn - you are not expected to know everything coming in, but you should continuously learn new techniques on the job * The ability to communicate clearly, acknowledge mistakes, and disagree when necessary * Demonstrable passion for offensive security * Experience reading, writing and debugging C++ and Python code * Basic experience with memory exploitation techniques * Demonstrable experience with web exploitation techniques and tools (e.g. PortSwigger lab scoreboards) * Excellent written and oral communication skills, We are looking for a highly motivated and talented Application Security Engineer to join their team. In this role, you will help make security decisions that impact millions of users while gaining hands-on experience in exploit development, vulnerability research, and CVE discovery. The ideal candidate combines an attacker mindset with strong attention to detail and enjoys collaborating with engineering teams to build secure, scalable solutions. ## Description * Reproduce and triage incoming vulnerabilities from security automation/bug bounty programs, then propose granular fixes to engineers * Discover vulnerabilities and construct exploits for core Parallels applications such as Parallels * Remote Application Server * Assist in the CVE disclosure process * Provide threat models and design reviews for teams throughout the company * Assist in tuning existing static analysis, dynamic analysis, and dependency management tools ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Using AI Without Losing Your Skills](https://www.wearedevelopers.com/videos/2045-using-ai-without-losing-your-skills) - [2021: Familiar APIs on Kickass Runtimes #slideless](https://www.wearedevelopers.com/videos/102-2021-familiar-apis-on-kickass-runtimes-slideless) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)