> Markdown version of [/jobs/ext/2714457-application-security-architect](https://www.wearedevelopers.com/jobs/ext/2714457-application-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect - **Company:** Nerdio, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Software System Penetration Testing, C Sharp (Programming Language), Code Review, Cross-Site Request Forgery, Open Web Application Security, Secure Coding, Software Engineering, SQL Injection, ReactJS, Software Security, Cross-Site Scripting (XSS), Gitlab, Restful APIs, Api Management, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/application-security-architect-nerdio-8300925 ## About the Role * 10+ years of experience in application security or a related field, with a passion for learning and growing your skillset. * Someone who has led the initial inception of the Application Security program from the ground up. * A solid understanding of security fundamentals and common vulnerabilities (e.g., XSS, CSRF, SQL Injection). * A knack for identifying potential risks and collaborating with engineers to find effective solutions. * The ability to effectively communicate security concepts to both technical and non-technical audiences. Preferred Qualifications * Familiarity with one or more programming languages (C#, React, JavaScript and REST APIs, to aide in code review and vulnerability analysis. * Actively engaged in the security community through participation in B-sides conferences, OWASP chapter activities, and regular contributions to GitLab repositories, fostering continuous learning and collaboration. ## Description Nerdio's growing security team seeks an Application Security Architect to help us enhance the security of our cutting-edge applications. Partnering closely with our engineering and product teams, you will play a vital role in applying your security expertise throughout the software development lifecycle. The architect will be a key contributor to evolving the Application Security program from inception. What You'll Do * Establish and continuously improve the AppSec program's strategy, processes, and tooling. * Collaborate with engineers to integrate security best practices into design reviews, threat modeling, code reviews, and penetration testing. * Participate in secure code review and penetration testing efforts, honing your skills with hands-on experience under the guidance of senior team members. * Contribute to deep-dive security reviews of our web, mobile, and API products to ensure they adhere to secure design principles. * Participate in security training and share your learnings with the broader engineering team to foster a culture of security awareness. * Assist in incident response to gain valuable real-world experience and help protect Nerdio's systems and data. * Gain exposure to SAST/DAST tools and risk assessment, building a foundation for future growth. * Mentor junior members of the AppSec team to support their professional growth and skill development. ## Related Videos - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)