> Markdown version of [/jobs/ext/2735392-sr-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2735392-sr-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Application Security Engineer - **Company:** Global Business Travel Group, Inc. - **Location:** Topeka, KS, United States (Remote available) - **Experience:** Expert - **Salary:** $84,294.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Amazon Web Services, Authentication Protocols, Microsoft Azure, Cloud Computing Security, DevOps, Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Cloud Services, Secure Coding, Software Engineering, TypeScript, Cloud Platform System, Software Security, Devsecops, Static Application Security Testing, Golang, Programming Languages, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://www.kansasworks.com/jobs/13659320 ## About the Role + 5+ years of professional software development experience with demonstrable expertise in major programming languages (Python, Go, Java, JavaScript/TypeScript); 3+ years of hands-on application security or DevSecOps experience + Strong knowledge of OWASP Top 10 and related secure coding practices; deep understanding of API security, authentication protocols, and secure API design + Strong cloud security expertise with at least one major cloud service provider (AWS, Azure, or GCP); deep understandin ## Description We are seeking an experienced Senior Application Security Engineer to join our team in the corporate travel industry. This remote position requires a unique blend of application development experience and security expertise to build, secure, and maintain our cloud-native infrastructure. The ideal candidate will have transitioned from application development into application security, bringing a developer's mindset to security and operations, and will mentor others while helping shape how the organization builds and governs secure software. What You'll Do: + Work with DevOps teams to design, implement, and maintain secure CI/CD pipelines that integrate security testing at every stage of the software development lifecycle + Implement and tune automated security scanning, including SAST, DAST, SCA, and container scanning + Deploy and support API security tools, ensuring findings are consistently reported to a central aggregator + Collaborate with development teams to promote secure coding practices and provide security guidance throughout the development process + Evaluate and help govern the secure use of agentic AI coding tools across engineering teams, establishing guardrails and detection strategies to mitigate risks such as hallucinated dependencies, injected vulnerabilities, and insufficient oversight + Ensure compliance with industry standards relevant to the travel industry, including PCI-DSS, GDPR, and SOC 2 + Build KPI and metrics reporting for application security initiatives and present findings to leadership as needed + Mentor junior engineers and promote a security-first culture across engineering teams ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)