> Markdown version of [/jobs/ext/2976938-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/2976938-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** SECURITY PRODUCTS, INC. - **Location:** United States (Remote available) - **Salary:** $120,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Agile Methodology, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Engineering, Code Review, DevOps, Python (Programming Language), Open Web Application Security, Software Engineering, Web Applications, Google Cloud, Cloud Platform System, Software Security, Kubernetes, Free and Open-Source Software, Docker, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** September 18, 2026 - **Apply:** https://jobs.military.com/career/339773/product-security-engineer-application-security-remote-california-ca-sunnyvale ## About the Role * A moderate understanding of how software products are created and shipped in Agile/DevOps like environments\n * Moderate experience with threat modeling, especially using STRIDE\n * Code review experience for apps built with Go (Golang), Python, or Java\n * Knowledge of secure configuration of cloud-native and containerized apps in one or more Cloud environments (GCP, Azure, AWS)\n * Experience using and/or maintaining commercially available AppSec tools like SAST, DAST, CSPM, DSPM, and ASPM suites\n * An understanding of common software weaknesses that impact cloud and web applications (not just the OWASP Top 10) and experience in application penetration testing\n * Comfort with collaborating across technical teams: asking technical questions, challenging assumptions, getting or providing context for decisions, etc.\n * Experience with driving ambiguous research projects\n * Proven experience utilizing AI technologies to enhance decision-making, streamline workflows and processes, improve efficiency and drive business outcomes.\n, * Self-motivated to identify security problems and engage with teams to find solutions\n * Demonstrable experience developing/maintaining automation for application security tasks and defect identification\n * Example(s) of having a positive working relationship with product engineers (software product development experience is a huge bonus)\n * Knowledge of Docker and Kubernetes (k8s)\n * Can explain and demonstrate the limitations of AI assisted development and associated security implications\n * Engaged in providing security enhancements to open source projects\n * Experience with threat intelligence driven testing and adversarial emulation\n ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)