> Markdown version of [/jobs/ext/2721305-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2721305-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** LINCOLN FINANCIAL GROUP - **Location:** Philadelphia, PA, United States (Remote available) - **Experience:** Experienced - **Salary:** $110,000.0 - $150,000.0 - **Contract:** Franchise - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Engineering, Cyber Security, Github, OAuth, OpenID, Open Web Application Security, Systems Development Life Cycle, Fortify (Software), Security Assertion Markup Language (SAML), Session Management, Software Engineering, Web Applications, Delivery Pipeline, Software Security, Veracode, GWAPT, Containerization, Gitlab-ci, Kubernetes, Information Technology, Codebase, Cloud Migration, Restful APIs, Cyber Warfare, Docker, Jenkins, Microservices - **Published:** September 4, 2026 - **Apply:** https://www.careerjet.com/jobad/us9bb8c4554c8317c0707f84e8c3fbf869 ## About the Role * Bachelor's degree in Computer Science, Information Security, or equivalent practical experience. * 4+ years of combined experience in software engineering, cloud engineering, or application security, including direct hands-on security responsibilities. * Demonstrated capability in executing threat modeling frameworks (STRIDE, PASTA, or equivalent) and translating findings into actionable developer tasks. * Strong technical depth in OWASP Top 10, OWASP ASVS, CWE Top 25, and modern attack patterns against web applications, REST APIs, and microservices. * Experience embedding security tooling into modern CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins). * Solid working knowledge of enterprise authentication and authorization standards (OAuth 2.0, OIDC, SAML) and session security. * Familiarity with containerization and cloud-native architecture (Docker, Kubernetes) and their associated security vectors. * Ability to communicate risk and remediation guidance to engineering audiences in language they will accept and act on. Preferred Qualifications * Experience configuring and tuning enterprise code scanning platforms (Fortify, Veracode, Wiz Code). * Exposure to Azure/AWS security controls, CSPM, and CNAPP tooling (e.g., Wiz). * Hands-on experience with API security testing, runtime application protection (RASP), and WAF tuning. * Active professional security certifications such as OSCP, OSWE, GWAPT, GPEN, or CISSP. * Familiarity with supply chain security frameworks (SLSA, S2C2F, OpenSSF Scorecard). * Prior work in a distributed, multi-tenant, or franchise-like operational environment. ## Description We are seeking an Application Security Engineer to join our Cyber Defense & Engineering (CDE) team who will be responsible to establish, scale, and own the Application Security operating model across a decentralized product engineering organization undergoing cloud modernization. They will be focused on creating a scalable AppSec capability rather than managing a legacy program. They will design risk-tiering frameworks, integrate automated security gates into CI/CD pipelines, lead threat modeling for cloud migrations, and establish a Security Champions network to embed secure coding practices directly into development teams., * Catalog applications, development pipelines, source repositories, and existing security tools across decentralized teams to establish an accurate baseline. * Create and deploy a risk-tiering framework to prioritize security efforts and resources on high-risk applications. * Define, publish, and socialize a minimum application security baseline across engineering leadership regardless of team tooling or SDLC variations. * Build, launch, and lead a Security Champions network across distributed product engineering teams to scale security practices natively. * Lead threat modeling exercises (STRIDE/PASTA) for monolith-to-microservices re-architecture, containerization, and cloud migration projects. * Provide technical architectural guidance during cloud migration decisions to identify security trade-offs before architecture is locked. * Integrate static and dynamic security testing tools seamlessly into CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI, Jenkins). * Triage, validate, and prioritize vulnerabilities from automated scanners, penetration tests, bug bounty programs, and detection alerts. * Partner with Security Operations and Incident Response teams on application-layer incidents, analyzing attack paths and exploit feasibility. * Define and track key performance indicators for application coverage, risk tiering, vulnerability density, and remediation velocity. * Evaluate and enforce secure authentication and authorization implementation, including OAuth 2.0, OIDC, SAML, and session management. * Review unfamiliar codebases across diverse languages, configure security scanning engines, and partner with developers to guide remediation., Job Title: Application Security Engineer Location: Philadelphia, PA 19103 (Hybrid) Type: 6-Month Contract-to-Hire (CTH) Job Summary We are seeking an Application Security Engi… + 1 day ago ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)