Application Security Engineer

Irvine Technology Corporation
New York, NY, United States
5 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$240,000.0 - $260,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Microsoft Azure Software as a Service Continuous Integration Github Open Web Application Security Large Language Models Software Security Mitre Att&ck Gitlab-ci Kubernetes Terraform
+3 more
Jenkins Static Application Security Testing Dynamic Application Security Testing

Job description

Our client is looking for an experienced Application Security Engineer to build, mature, and scale their application security program from the ground up. In this role you’ll embed directly with Product and Engineering teams to secure both third-party SaaS applications and home-grown software, serving as both a trusted security consultant and a hands-on engineer. You’ll review complex API designs, lead threat modeling on new features, build custom security tooling, and automate security controls directly into CI/CD pipelines. This is a high-impact opportunity for someone who brings an automation-first mindset and knows how to balance developer velocity with risk-informed pragmatism, bridging the cultures of development, security, and operations., * Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tooling into CI/CD pipelines for home-grown applications

  • Lead security design and threat modeling sessions with Product and Engineering teams based on OWASP Top 10 and MITRE ATT&CK
  • Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks
  • Define AppSec coverage, tooling, and assessment processes from scratch across the application landscape
  • Develop secure Infrastructure as Code patterns and validate security controls for Azure and Kubernetes

Requirements

  • Significant hands-on application security experience, including expert knowledge of OWASP Top 10, API Security Top 10, and OWASP LLM Top 10 and how common vulnerability classes manifest in production
  • Proficiency integrating SAST/SCA/DAST, container/IaC scanners, and secret scanning into one or more CI/CD stacks (GitHub Actions, GitLab CI, Azure DevOps, Jenkins)
  • Proficiency in Terraform/IaC, Kubernetes, and cloud provider security, with Azure preferred
  • Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch
  • Experience building security tooling or automation; policy gates with OPA/Gatekeeper or Kyverno a plus

About the company

Irvine Technology Corporation (ITC) connects top talent with exceptional opportunities in IT, Security, Engineering, and Design. From startups to Fortune 500s, we partner with leading companies nationwide. Our AI recruiter, Avery helps streamline the first step of your journey-so we can focus on what matters most: helping you grow. Join us. Let us ELEVATE your career!

Irvine Technology Corporation provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Irvine Technology Corporation complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · World Congress 2023

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

57 sec

Extracting API schemas automatically during continuous integration builds

Axel Barbier · World Congress 2023

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all