Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
Our client is looking for an experienced Application Security Engineer to build, mature, and scale their application security program from the ground up. In this role you’ll embed directly with Product and Engineering teams to secure both third-party SaaS applications and home-grown software, serving as both a trusted security consultant and a hands-on engineer. You’ll review complex API designs, lead threat modeling on new features, build custom security tooling, and automate security controls directly into CI/CD pipelines. This is a high-impact opportunity for someone who brings an automation-first mindset and knows how to balance developer velocity with risk-informed pragmatism, bridging the cultures of development, security, and operations., * Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tooling into CI/CD pipelines for home-grown applications
- Lead security design and threat modeling sessions with Product and Engineering teams based on OWASP Top 10 and MITRE ATT&CK
- Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks
- Define AppSec coverage, tooling, and assessment processes from scratch across the application landscape
- Develop secure Infrastructure as Code patterns and validate security controls for Azure and Kubernetes
Requirements
- Significant hands-on application security experience, including expert knowledge of OWASP Top 10, API Security Top 10, and OWASP LLM Top 10 and how common vulnerability classes manifest in production
- Proficiency integrating SAST/SCA/DAST, container/IaC scanners, and secret scanning into one or more CI/CD stacks (GitHub Actions, GitLab CI, Azure DevOps, Jenkins)
- Proficiency in Terraform/IaC, Kubernetes, and cloud provider security, with Azure preferred
- Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch
- Experience building security tooling or automation; policy gates with OPA/Gatekeeper or Kyverno a plus
About the company
Irvine Technology Corporation (ITC) connects top talent with exceptional opportunities in IT, Security, Engineering, and Design. From startups to Fortune 500s, we partner with leading companies nationwide. Our AI recruiter, Avery helps streamline the first step of your journey-so we can focus on what matters most: helping you grow. Join us. Let us ELEVATE your career!
Irvine Technology Corporation provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Irvine Technology Corporation complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Walking Into The Era of Supply Chain Risks
Dev Digest 134 - Where pixels sing?
Dev Digest 120 - Apple and peers