> Markdown version of [/jobs/ext/2722845-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2722845-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Packsize, LLC - **Location:** Salt Lake City, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software as a Service, Cloud Computing Security, Code Review, Firmware, Information Systems Security Architecture Professional, Key Management, Open Source Technology, Systems Development Life Cycle, Secure Coding, Software Deployment, Software Engineering, Software Security, Service Stack, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/application-security-engineer-yrh-packsize-llc-8461300 ## About the Role * Office-based work environment; ability to sit for extended periods and move about the office as needed. * Periodic remote work; comfortable with a hybrid office setting. * Ability to travel up to 15%, including international travel. ## Description Packsize is seeking an experienced Application Security Engineer to champion secure software development across our technology stack. You will collaborate closely with development and product teams to integrate robust security practices into every stage of our SDLC, ensuring that security is a foundational element of our technology solutions and product innovations., * Embed with software engineering teams to guide the secure design, development, and deployment of applications, advocating for "security by design." * Drive the adoption of automated security tools and processes within the software development lifecycle to detect and remediate vulnerabilities early. * Conduct threat modeling, code reviews, and vulnerability assessments for web, cloud, and OT (Operational Technology) applications and services. * Lead security initiatives targeting improvements in Packsize's application and machine software environments. * Serve as a subject matter expert for application security within cross-functional forums, providing clear guidance on secure coding, secure architecture, and best practices. * Collaborate on the creation, maintenance, and communication of security policies and secure SDLC standards, ensuring alignment with industry regulations and compliance mandates. * Identify, assess, and prioritize application security risks and work with engineering and business leaders to develop effective remediation strategies. * Assess third-party and open-source dependencies for security risks, ensuring that vendor and supply chain security meet Packsize standards. * Respond to security incidents involving applications, lead root cause analyses, and drive post-incident improvements. * Perform regular security testing, such as SAST, DAST, and penetration testing, to validate the security of applications. * Provide expert input on cryptography and key management for applications, ensuring robust protection of data in transit and at rest. * Evaluate and recommend new security solutions and tools to continually improve Packsize's application security posture., * 10+ years of security-related experience, with at least 5+ years in an application security or software security engineering role. * Deep experience working with software development teams to embed security practices into the software development lifecycle and release processes. * Technical proficiency in secure coding practices, application vulnerability scanning, and remediation. * Experience securing OT (Operational Technology) and machine software environments, especially challenges like remote device deployment and secure firmware/software delivery. * In-depth knowledge of cloud security best practices and architecture, especially for SaaS or IoT products. * Demonstrated experience delivering and implementing technical security solutions for complex application environments. * Strong background conducting security assessments, risk analyses, and security testing for applications. * Familiarity with compliance requirements (GDPR, SOX) and security frameworks (SOC2, ISO, NIST) as they relate to application development and deployment. * Excellent interpersonal skills; able to influence, educate, and partner with technical and business stakeholders at all levels. * Passion for mentoring developers on secure coding and application security best practices. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)