> Markdown version of [/jobs/ext/2818422-senior-application-security-engineer-blue-team](https://www.wearedevelopers.com/jobs/ext/2818422-senior-application-security-engineer-blue-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer (Blue Team) - **Company:** Altruist Corp - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $170,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Amazon Web Services, Cloud Computing, Code Review, Cyber Security, Computer Engineering, Continuous Integration, Spring Framework, Secure Coding, Software Security, GWAPT, Kubernetes, Information Technology, Terraform, Blue Team (Cyber Security), Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=61d10ec57ed31b84 ## About the Role * Experience - 4+ years of experience working as an Application/Product Security Engineer: + Extensive experience with security assessments, security design reviews, or threat modeling + Hands-on secure code review (Java/Spring or similar) + Experience operating SAST/DAST/SCA and secrets-scanning tooling in a CI/CD pipeline + Strong ability to work independently * Education - A B.A. / B.S. degree in relevant fields such as Computer Science or Computer Engineering or Information Security or relevant experience * Technical aptitude - You're technologically savvy and can easily get up to speed on modern tech stacks (i.e., Java, Spring, Terraform, Kubernetes, etc.) * Ownership - The pride you put into every aspect of your work is unparalleled and undeniable * Superb communication - Intentional dialogue is a superpower. You listen as well as you share your perspective with others. * Resilience - We're inspired by your unwavering determination to achieve success, no matter the adversity you face along the way. * Assurance - Your confidence is brilliant, yet ego-less. You possess a strong knowledge base, the ability to discover the unknown, and are open to differing perspectives. * Creative problem solving - Identifying the problem is simply not enough. You're instinctually creative with your approach in finding solutions to roadblocks. Bonus points if you bring * Experience working in regulated environments (fintech / financial services) * Experience building AppSec automation or a "paved road" for developers * Cloud (AWS) and API security experience * Relevant certifications (e.g., CSSLP, GWAPT, OSCP) ## Description * Educate and train development teams on secure coding practices and emerging security threats. * Perform technical security assessments and code reviews across our Java/Spring services * Engage in threat modeling to anticipate potential security threats and develop strategies to mitigate them. * Assist teams in building libraries, repeatable patterns, and paved-road components that ensure security is a part of every new feature. * Own and tune SAST, DAST, software composition analysis (SCA), and security tooling in CI/CD pipelines; triage findings and drive them to remediation with clear prioritization. * Partner with engineering to close service-to-service authentication/authorization gaps and other systemic issues. * Work with Detection & Response and our offensive security engineers to turn findings into durable detections and prevention. * Contribute to our secure SDLC standards and developer security guardrails. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)