Application Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+18 more
Job description
Our client is seeking an experienced Application Security Engineer to serve as a trusted security advisor embedded within our Agile development organization. This role will partner closely with software engineering teams to integrate security throughout the Software Development Lifecycle (SDLC), helping ensure applications and APIs are designed, built, and deployed securely. This individual will play a critical role in advancing application security practices, driving DevSecOps maturity, and helping development teams proactively identify and remediate security risks. The ideal candidate combines strong application security expertise with the ability to collaborate effectively with developers and technical stakeholders. About the Team
- Support approximately 100 software engineers across multiple engineering teams.
- Partner directly with 6 Scrum teams in an Agile environment.
- Join a highly visible Application Security function with significant opportunity to influence processes and strategy.
- Work primarily within a Microsoft-based technology ecosystem featuring C#, .NET Framework, SOAP services, APIs, and enterprise applications.
- Help drive the evolution and maturity of a growing DevSecOps and Application Security program., * Serve as the primary Application Security advisor for development teams.
- Embed security best practices throughout the Software Development Lifecycle (SDLC).
- Conduct threat modeling exercises and security risk assessments for applications and APIs.
- Review application architectures, designs, data flows, and new feature implementations from a security perspective.
- Validate, triage, and prioritize vulnerabilities identified through:
- SAST tools
- DAST tools
- Software Composition Analysis (SCA)
- Vulnerability assessments
- Penetration testing activities
- Provide remediation guidance and work directly with development teams to resolve security findings.
- Participate in sprint planning sessions and Agile ceremonies to ensure security requirements are incorporated early in the development process.
- Support the deployment, tuning, and ongoing effectiveness of application security testing programs.
- Promote secure coding practices and mentor engineering teams on application security concepts.
- Assist in developing and maturing DevSecOps processes, standards, and automation capabilities.
- Translate technical security risks into actionable business recommendations.
Requirements
- 5+ years of experience in Application Security, Secure Software Development, DevSecOps, or a related cybersecurity discipline.
- Hands-on experience performing threat modeling and security architecture reviews.
- Strong understanding of vulnerability management and remediation processes.
- Experience supporting security testing programs utilizing:
- SAST
- DAST
- SCA
- Knowledge of OWASP Top 10, SANS/CWE vulnerabilities, and secure coding principles.
- Experience partnering directly with software development teams.
- Understanding of secure SDLC methodologies and DevSecOps practices.
- Ability to analyze source code and identify security concerns.
- Strong verbal and written communication skills.
Preferred Qualifications
- Experience working in C#/.NET or Java development environments.
- Previous experience as a software engineer who transitioned into security.
- Experience securing APIs, web applications, and enterprise software platforms.
- Familiarity with security tools such as:
- Burp Suite
- OWASP ZAP
- Wireshark
- Nessus
- Qualys
- Metasploit
- Experience with WAF technologies, API security platforms, and API gateways.
- Exposure to Azure and/or AWS security controls.
- Knowledge of security frameworks such as NIST, ISO 27001, OWASP SAMM, Microsoft SDL, or BSIMM.
- Experience integrating security controls into CI/CD pipelines., The ideal candidate is a security-first professional who understands how modern applications are built and can effectively influence engineering teams. While familiarity with software development is valuable, we are prioritizing deep Application Security expertise, including threat modeling, vulnerability management, security testing, and secure SDLC practices.
Benefits & conditions
Why Join Us?
- Opportunity to help shape and influence the Application Security program.
- High-visibility role with direct impact across engineering teams.
- Strong executive support for cybersecurity and technology initiatives.
- Collaborative, growth-oriented culture.
- Company-wide focus on innovation and AI-driven transformation.
- Competitive compensation, benefits, and PTO.
- Opportunity to make a meaningful impact while helping mature security capabilities across a large development organization.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
The 12 Best Jobs for Software Engineers
9 Ways to Make Money Hacking
Fully Remote Software Engineer Jobs