> Markdown version of [/jobs/ext/2680032-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2680032-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Environmental Systems Research Institute, Inc. - **Location:** Redlands, CA, United States - **Experience:** Expert - **Salary:** $93,600.0 - $157,560.0 - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Application Layers, Software System Penetration Testing, Microsoft Azure, Bash Shell, C Sharp (Programming Language), Code Review, Encodings, Communications Protocols, Cyber Security, Github, Hypertext Transfer Protocols (HTTP), Python (Programming Language), OAuth, Open Source Technology, OpenID, Windows PowerShell, Web Application Security, Software Engineering, SQL Databases, TypeScript, Software Vulnerability Management, Esri GIS (Software), GitHub Copilot, Software Security, Kubernetes, Information Technology, Restful APIs, Devsecops, Dynamic Application Security Testing - **Published:** September 2, 2026 - **Apply:** https://www.esri.com/careers/5136168007 ## About the Role * 5+ years of experience in application security, including manual and automated code reviews, manual penetration testing, dynamic application security testing, and false positive analysis of code, pen test, and open-source security findings * Demonstrated experience determining risk based on analysis/findings using a consistent risk management framework * Proven ability to develop automations/applications using Python, Typescript, Java, or PowerShell * Experience creating and maintaining reusable GitHub Actions workflows, with expertise in all aspects of GitHub workflow management * Hands-on experience working in a DevSecOps environment built on Kubernetes with a strong knowledge of Kubernetes security best practices * Ability to read and analyze code for security and design vulnerabilities * Solid understanding of common web application security standards (HTTP, OAuth, OIDC, REST, and more) * Experience working with cloud platforms, specifically AWS and Azure * Willingness to learn new skills and enhance workflows using various AI tools * US citizenship and willingness and ability to maintain a US Security Clearance * Bachelor's degree in computer science or related field, * Proficiency in any of the following languages: C#, Python, Bash/Shell, PowerShell, JavaScript, SQL, Java * Familiarity with AI-assisted coding practices, including tools such as GitHub Copilot, and an understanding of the security implications and risks introduced by AI-generated code * Practical experience interpreting findings from application pen testing, code scanning and open-source scanners to determine the risk and collaborate with developers to resolve them * Understanding of layer 2-7 communication protocols, common encoding and encryption schemes, and algorithms #LI-TM1 ## Description As someone experienced with securing a wide variety of applications, you are looking for an opportunity to use your skills in an innovative and technology-oriented environment. As an Application Security Engineer at Esri, you will fill a critical role in helping secure Esri's intellectual property and sensitive data against a variety of complex threats with support from all levels of leadership. Our Application Security team collaborates closely with the application development, DevSecOps, and information security departments to design security into our applications up front, perform application layer security testing, and assist developers with vulnerability remediation. We value collaboration, pragmatic security, and continuous improvement. We welcome you to join Esri, where you can make a real difference every day!, * Design, operate, and continuously improve application security testing capabilities and pipelines * Assess application risks and recommend mitigations * Perform application layer security reviews of the code developed by our application teams, across multiple languages and frameworks used internally * Assist with application layer penetration testing to identify potential issues * Provide application security guidance and mentorship to development teams as needed ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)