> Markdown version of [/jobs/ext/287599-senior-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/287599-senior-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Application Security Engineer - **Company:** S. Walker, Inc. - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $170,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Code Review, Cyber Security, Key Management, Open Web Application Security, PCI Data Security Standards, Secure Coding, Software Security, Mitre Att&ck, Containerization, Restful APIs, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bdbc241f953aca4f ## About the Role Do you have experience in Training employees on security practices?, * 5+ years in cybersecurity, specifically focused on Application Security. * Hands-on coding experience and familiarity with modern development stacks (e.g., microservices, REST APIs, containerized environments). * Proficiency with SAST/DAST tools, threat modeling methodologies (e.g., MITRE ATT&CK), cryptography concepts (key management, encryption standards), and cloud security services (AWS, GCP, or Azure). * Excellent communication, collaboration, and problem-solving skills in a fast-paced, cross-functional setting. Nice To Have * Industry certifications (CISSP, CSSLP, OSCP, CEH) Experience with compliance frameworks (PCI DSS, SOC 2, ISO 27001). * Exposure to fintech/payments environments ## Description As a Senior Application Security Engineer, you'll be a linchpin in ensuring our products and services are built securely from the ground up. You'll design and implement security best practices within our applications, conduct robust testing, and empower engineering teams to proactively address vulnerabilities., * Conduct systematic threat modeling (e.g., leveraging the MITRE ATT&CK framework) to identify risks, define attack paths, and propose mitigations early in the development lifecycle. * Perform in-depth security architecture reviews to ensure applications and microservices follow secure design principles. * Collaborate with engineering teams to conduct code reviews, pinpoint vulnerabilities, and champion OWASP Top 10 best practices. * Integrate SAST and DAST into CI/CD pipelines, ensuring continuous and automated detection of security flaws. * Analyze testing reports and guide teams toward swift, effective remediation strategies. * Perform or coordinate targeted penetration tests on critical applications and systems. * Document findings and partner with engineers to implement sustainable fixes. * Advise on symmetric and asymmetric encryption mechanisms to safeguard data at rest and in transit. * Oversee secure key management, ensuring cryptographic libraries and protocols are properly utilized. * Develop and deliver training on secure coding fundamentals and OWASP principles. * Lead the "shift-left" security movement by embedding security considerations in early stages of development-a strong development background is required to effectively collaborate and coach. * Investigate and document application-focused security incidents. * Maintain and refine incident response playbooks, integrating lessons learned into ongoing improvements. * Align AppSec practices with PCI DSS, SOC 2, and relevant frameworks to support regulatory audits. * Work closely with Risk, Fraud, and Compliance teams to ensure continuous alignment between engineering, security, and business goals. ## Related Videos - [Rest API Antipatterns](https://www.wearedevelopers.com/videos/100208-rest-api-antipatterns) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [REST In Peace: Why LLMs Can't CRUD](https://www.wearedevelopers.com/videos/100272-rest-in-peace-why-llms-can-t-crud) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)