> Markdown version of [/jobs/ext/2712365-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2712365-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** LVT LLC - **Location:** American Fork, UT, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** HTML, PHP (Programming Language), Artificial Intelligence, Software System Penetration Testing, Cloud Computing, Code Review, Cyber Security, Continuous Integration, Github, OSI Models, Network Protocols, Node.Js, Open Web Application Security, Systems Development Life Cycle, Cloud Services, Next.js, Software Engineering, Software Vulnerability Management, Circleci, ReactJS, NestJS, Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-application-security-engineer-lvt-7895090 ## About the Role * Proven Experience: At least 3+ years of professional experience in an Information Security role with a dedicated focus on modern application environments. * Cloud Proficiency: 3+ years of hands-on security experience with AWS and other cloud service platforms. * Modern Stack Familiarity: Comfortable navigating common web languages and frameworks such as HTML, PHP, Node.js, React.js, Nest.js, and Next.js. * Pipeline Expertise: A solid understanding of CI/CD tools and artifacts including GitHub, Docker, JFrog, CircleCI, and ArgoCD. * Technical Depth: A comprehensive understanding of common application vulnerabilities (OWASP Top 10) and the orchestration of automated tools used to combat them (SAST, DAST, SCA). * IT Foundations: Strong grasp of foundational IT domains, including operating systems, networking protocols, and the OSI model. * Compliance Awareness: Familiarity with standard security and regulatory compliance frameworks such as CIS, NIST, ISO/IEC 27001, SOC2, or FedRAMP. * Exceptional Communicator: Ability to articulate risk with clarity and professional poise, maintaining high levels of personal integrity while working with cross-functional partners. * Preferred Credentials: A degree in IT/Security or industry certifications such as Security+, OSCP, GPEN, or ITCA are highly valued., LVT IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. All candidates must pass a drug screening and background check upon employment. Some roles may also require passing a federal background check and fingerprinting. Must be authorized to work in the U.S. If reasonable accommodation is needed to participate in the job application or interview process, and/or to perform essential job functions, please reach out to your recruiter. ## Description As a Senior Application Security Engineer at LVT, you will be a cornerstone of our commitment to building secure-by-design technology. You will partner deeply with our Engineering and Product teams to weave advanced security protocols into every layer of our Software Development Lifecycle (SDLC). This isn't just about finding bugs; it's about architecting a proactive security culture and scaling our defenses alongside our rapid growth. You will serve as a technical expert, mentor, and advocate, ensuring our AI-driven platform remains as resilient as it is innovative., * Strategic Integration: Partner with Product and Engineering to embed reproducible, high-standard security practices directly into the SDLC. * Defense Engineering: Develop and maintain sophisticated manual and automated security processes to identify, evaluate, and mitigate risks across our software ecosystem. * Offensive Security: Lead proactive security initiatives including threat modeling, deep-dive code reviews, and offensive security exercises/penetration testing. * Vulnerability Management: Architect and manage the deployment of vulnerability scanning tools, driving the remediation process to ensure rapid resolution of identified issues. * Policy Stewardship: Assist in the development and continuous improvement of secure development policies and procedural documentation. * Technical Translation: Communicate complex vulnerability details and risk assessments to both technical and non-technical stakeholders, ensuring organizational alignment. * Security Culture: Mentor junior team members and foster a strong, transparent security culture across the company. * Impact Measurement: Success in this role is measured by the reduction of critical vulnerabilities in production, the speed of remediation cycles, and the successful adoption of security tools by the broader engineering team. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)