> Markdown version of [/jobs/ext/2502229-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2502229-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Irvine Technology Corporation - **Location:** New York, NY, United States - **Salary:** $240,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Microsoft Azure, Software as a Service, Continuous Integration, Github, Open Web Application Security, Large Language Models, Software Security, Mitre Att&ck, Gitlab-ci, Kubernetes, Terraform, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 31, 2026 - **Apply:** https://www.dice.com/job-detail/cb8c7a4f-e7a7-43c3-9e08-966203285be4 ## About the Role * Significant hands-on application security experience, including expert knowledge of OWASP Top 10, API Security Top 10, and OWASP LLM Top 10 and how common vulnerability classes manifest in production * Proficiency integrating SAST/SCA/DAST, container/IaC scanners, and secret scanning into one or more CI/CD stacks (GitHub Actions, GitLab CI, Azure DevOps, Jenkins) * Proficiency in Terraform/IaC, Kubernetes, and cloud provider security, with Azure preferred * Experience building or maturing an AppSec program where coverage, tooling, or process needed to be defined from scratch * Experience building security tooling or automation; policy gates with OPA/Gatekeeper or Kyverno a plus ## Description Our client is looking for an experienced Application Security Engineer to build, mature, and scale their application security program from the ground up. In this role you'll embed directly with Product and Engineering teams to secure both third-party SaaS applications and home-grown software, serving as both a trusted security consultant and a hands-on engineer. You'll review complex API designs, lead threat modeling on new features, build custom security tooling, and automate security controls directly into CI/CD pipelines. This is a high-impact opportunity for someone who brings an automation-first mindset and knows how to balance developer velocity with risk-informed pragmatism, bridging the cultures of development, security, and operations., * Embed SAST, SCA, DAST, container/IaC scanning, and secret detection tooling into CI/CD pipelines for home-grown applications * Lead security design and threat modeling sessions with Product and Engineering teams based on OWASP Top 10 and MITRE ATT&CK * Review API designs and integrations to eliminate authentication anti-patterns, token mismanagement, and injection risks * Define AppSec coverage, tooling, and assessment processes from scratch across the application landscape * Develop secure Infrastructure as Code patterns and validate security controls for Azure and Kubernetes ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)