> Markdown version of [/jobs/ext/2805200-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2805200-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Open Systems Inc. - **Location:** New York, NY, United States - **Salary:** $150,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Cyber Security, Computer Engineering, Information Management, Python (Programming Language), Open Web Application Security, Software Vulnerability Management, Software Security, Information Technology - **Published:** September 9, 2026 - **Apply:** https://www.opensystemstech.com/job/2458/application_security_engineer#apply-now-header ## About the Role * Proven experience in application security with a focus on application security testing and vulnerability management * Hands-on experience with Application Security tools * Strong understanding of common application vulnerabilities (e.g., OWASP Top 10) and mitigation techniques * Experience with threat modelling methodologies and tools * Proficiency in at least one programming language (e.g., Java, Python, JavaScript) * Excellent communication and collaboration skills, with the ability to work effectively in cross functional teams * Strong understanding of risk management * Degree in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity or equivalent) * Relevant security certifications (e.g. CISSP, CEH, CSSLP) or equivalent is preferred ## Description * Perform Application Security scans (e.g. DAST and SCA) on applications and APIs to identify security vulnerabilities and weaknesses * Triage security findings and collaborate with development teams to prioritize and remediate identified vulnerabilities * Drive threat modelling as a standard part of the SDLC, and develop and maintain threat models for critical applications, identifying potential security risks and proposing mitigations * Drive the Security Champions program, and define and promote secure coding practices, patterns, and standards across development teams * Conduct security reviews and provide guidance on security requirements for new features and projects * Assist in the analysis, selection and rollout of new application security tools, processes, and standards ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Swapping a Data Warehouse at Runtime: Zero-Downtime Migration Without Changing a Single Client](https://www.wearedevelopers.com/videos/100311-swapping-a-data-warehouse-at-runtime-zero-downtime-migration-without-changing-a-single-client) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)