> Markdown version of [/jobs/ext/2851637-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2851637-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Wrike, Inc - **Location:** Prague, NE, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Java (Programming Language), PHP (Programming Language), Artificial Intelligence, User Authentication, Code Review, Continuous Integration, Key Management, OAuth, OpenID, Secure Coding, Service-Oriented Architecture, Session Management, Software Engineering, TypeScript, Software Security, Backend, Bug Reporting, Front End Software Development, Automation Anywhere, Serverless Computing, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/91ebf28f-6b72-4525-87b9-f247c65dd2d5/application-security-engineer ## About the Role - Strong hands-on knowledge of common web and API security issues, authentication and session management concepts, secrets handling, and secure coding fundamentals. - Proven experience conducting secure code reviews in modern engineering environments, especially in Java, TypeScript, and PHP, with the ability to clearly explain security flaws and collaborate on effective remediation. - Experience leading or facilitating routine threat modeling for product features or services and translating outcomes into actionable security requirements. - Experience managing Application Security tools such as SAST, SCA, DAST, and secrets scanning solutions, as well as bug bounty platforms, with a focus on CI/CD integration, false positive reduction, and signal quality improvement. - Working knowledge of OAuth/OIDC, service-to-service authentication, secrets management, and foundational cloud or container security concepts. - Ability to prioritize findings based on exploitability, exposure, business impact, and remediation effort rather than relying on severity labels alone. - Strong written and verbal communication skills, with the ability to work effectively with engineers, technical leads, and product stakeholders. - Sound judgment when using AI-assisted workflows, treating AI as a copilot rather than an authority and validating correctness, exploitability, and business context before taking action. ## Description We're looking for an Application Security Engineer to help our product teams build and ship securely by default. In this role, you will work closely with engineering teams to identify risks early, strengthen secure design and coding practices, and enable teams to release features safely without creating unnecessary friction. This is a hands-on AppSec role for someone who can independently own recurring security work across multiple teams. You should be comfortable reviewing architecture and code, validating findings, guiding remediation, and making practical recommendations that balance security, product priorities, and delivery speed. ### **Your Impact:** - Own recurring Application Security activities for multiple product teams, including secure design reviews, threat modeling, code review, testing validation, and remediation guidance. - Assess vulnerabilities and findings from scanners, testing, bug reports, and internal reviews; distinguish meaningful risk from noise and help teams focus on the most important issues. - Validate security fixes and recommend compensating controls or practical alternatives when ideal remediation is not immediately possible. - Improve day-to-day AppSec workflows by tuning checks, refining rules, improving triage quality, and integrating security more effectively into developer workflows and CI/CD pipelines. - Help engineers understand security findings in practical product terms by providing clear prioritization and actionable remediation guidance. - Contribute to secure-by-default development practices by reinforcing standards, reference patterns, and review expectations. - Use structured AI workflows to support complex AppSec analysis, such as broader codebase review, design decomposition, review preparation, and documentation synthesis, while maintaining clear guardrails around prompt and context hygiene, human oversight, and output quality. , - Experience building AppSec automations, improving developer workflows, or tuning security controls in CI/CD environments. - Experience delivering practical secure coding guidance or lightweight internal security training. - Background in privacy-sensitive systems, cloud-native services, or multi-service architectures. - Experience supporting security for AI/ML product features, model-integrated systems, or governance of AI-assisted engineering workflows. ### **Team Dynamics:** You will partner closely with backend, frontend, mobile, platform, QA, and product teams on a daily basis, while also collaborating with peers across security, infrastructure, and compliance. Success in this role will require building trusted relationships with engineers, communicating clearly, and translating security concerns into practical guidance that teams can adopt quickly. ### **Our Work Style:** This is a collaborative, hands-on role embedded in the software development lifecycle. You will work closely with product and engineering teams to integrate security into design, development, and delivery processes, helping create secure-by-default outcomes without slowing teams down. You'll use a combination of secure review practices, threat modeling, AppSec tooling, CI/CD integrations, and structured AI-assisted analysis to support high-quality security decisions. What makes this role especially impactful is the opportunity to influence both product security posture and developer experience at scale, helping teams move fast while building securely. ### **Benefits & Perks:** ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)