> Markdown version of [/jobs/ext/3049062-security-engineer](https://www.wearedevelopers.com/jobs/ext/3049062-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** CivicPlus, LLC - **Location:** United States - **Experience:** Experienced - **Salary:** $70,300.0 - $101,300.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Artificial Intelligence, Software System Penetration Testing, C Sharp (Programming Language), Software as a Service, Cloud Engineering, Code Review, Cyber Security, Information Systems, Continuous Integration, Python (Programming Language), Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Security, Information Technology, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** September 24, 2026 - **Apply:** https://startup.jobs/application-security-engineer-civicplus-llc-10171990 ## About the Role * 3-7 years of experience in application security, secure development, penetration testing, or a related field. * Hands-on experience with application/security testing tooling (SAST, DAST, and/or IAST). * Experience integrating secure design principles into change management, code review, CI/CD pipelines, and secure development operations. * Security+, GSEC, GSSP, or equivalent certification. * Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Systems, or a related field (preferred). * Familiarity with secure coding practices across multiple languages (such as C#, Go, Java, JavaScript, or Python) and knowledge of cloud-native and SaaS application environments. * AI-forward mindset with a demonstrated ability to leverage AI tools to improve productivity, decision-making, and work quality. * Demonstrated ability to effectively use AI tools to enhance productivity and outcomes. ## Description * Perform security code reviews, threat modeling, and architecture reviews across all development projects as part of a secure Software Development Lifecycle (SDLC). * Collaborate with development teams to integrate secure design, secure coding standards, and security controls across the SDLC. * Identify, track, and validate vulnerabilities and security defects from security testing and scanning, partnering with development teams to prioritize remediation within compliance timeline requirements. * Coordinate external, independent penetration testing of production environments. * Lead application security testing, including static, dynamic, and interactive application security testing (SAST, DAST, IAST). * Serve as a subject matter expert on application security vulnerabilities (such as the OWASP Top 10) and emerging threats., * CivicPlus is currently unable to provide visa sponsorship for this position now or in the future. Applicants must be authorized to work in the US. * This position will remain open until October 7, 2026 at 4pm CT. We encourage you to apply as soon as possible, as applications will be reviewed on a rolling basis, and the posting may close earlier at the discretion of the Talent Acquisition team. * At CivicPlus, we embrace AI and automation as tools that help people work smarter, move faster, and focus on higher-value work that strengthens communities. We encourage thoughtful, responsible use of technology to improve efficiency, support innovation, and enhance the employee and customer experience-while keeping human judgment, collaboration, and accountability at the center of what we do. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)