Application Security Engineer

Corporate Brokers, LLC
United States
3 days ago
Apply on public-rest40.bullhornstaffing.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Agile Methodology Amazon Web Services Software System Penetration Testing Microsoft Azure Burp Suite C Sharp (Programming Language) Cyber Security Open Web Application Security Scrum Methodology
+18 more
Systems Development Life Cycle Secure Coding Software Engineering Data Streaming Wireshark Software Vulnerability Management Web Applications Enterprise Software Applications Software Security SOAPAPI Metasploit Nessus Api Gateway Devsecops Qualys Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Our client is seeking an experienced Application Security Engineer to serve as a trusted security advisor embedded within our Agile development organization. This role will partner closely with software engineering teams to integrate security throughout the Software Development Lifecycle (SDLC), helping ensure applications and APIs are designed, built, and deployed securely. This individual will play a critical role in advancing application security practices, driving DevSecOps maturity, and helping development teams proactively identify and remediate security risks. The ideal candidate combines strong application security expertise with the ability to collaborate effectively with developers and technical stakeholders. About the Team

  • Support approximately 100 software engineers across multiple engineering teams.
  • Partner directly with 6 Scrum teams in an Agile environment.
  • Join a highly visible Application Security function with significant opportunity to influence processes and strategy.
  • Work primarily within a Microsoft-based technology ecosystem featuring C#, .NET Framework, SOAP services, APIs, and enterprise applications.
  • Help drive the evolution and maturity of a growing DevSecOps and Application Security program., * Serve as the primary Application Security advisor for development teams.
  • Embed security best practices throughout the Software Development Lifecycle (SDLC).
  • Conduct threat modeling exercises and security risk assessments for applications and APIs.
  • Review application architectures, designs, data flows, and new feature implementations from a security perspective.
  • Validate, triage, and prioritize vulnerabilities identified through:
  • SAST tools
  • DAST tools
  • Software Composition Analysis (SCA)
  • Vulnerability assessments
  • Penetration testing activities
  • Provide remediation guidance and work directly with development teams to resolve security findings.
  • Participate in sprint planning sessions and Agile ceremonies to ensure security requirements are incorporated early in the development process.
  • Support the deployment, tuning, and ongoing effectiveness of application security testing programs.
  • Promote secure coding practices and mentor engineering teams on application security concepts.
  • Assist in developing and maturing DevSecOps processes, standards, and automation capabilities.
  • Translate technical security risks into actionable business recommendations.

Requirements

  • 5+ years of experience in Application Security, Secure Software Development, DevSecOps, or a related cybersecurity discipline.
  • Hands-on experience performing threat modeling and security architecture reviews.
  • Strong understanding of vulnerability management and remediation processes.
  • Experience supporting security testing programs utilizing:
  • SAST
  • DAST
  • SCA
  • Knowledge of OWASP Top 10, SANS/CWE vulnerabilities, and secure coding principles.
  • Experience partnering directly with software development teams.
  • Understanding of secure SDLC methodologies and DevSecOps practices.
  • Ability to analyze source code and identify security concerns.
  • Strong verbal and written communication skills.

Preferred Qualifications

  • Experience working in C#/.NET or Java development environments.
  • Previous experience as a software engineer who transitioned into security.
  • Experience securing APIs, web applications, and enterprise software platforms.
  • Familiarity with security tools such as:
  • Burp Suite
  • OWASP ZAP
  • Wireshark
  • Nessus
  • Qualys
  • Metasploit
  • Experience with WAF technologies, API security platforms, and API gateways.
  • Exposure to Azure and/or AWS security controls.
  • Knowledge of security frameworks such as NIST, ISO 27001, OWASP SAMM, Microsoft SDL, or BSIMM.
  • Experience integrating security controls into CI/CD pipelines., The ideal candidate is a security-first professional who understands how modern applications are built and can effectively influence engineering teams. While familiarity with software development is valuable, we are prioritizing deep Application Security expertise, including threat modeling, vulnerability management, security testing, and secure SDLC practices.

Benefits & conditions

Why Join Us?

  • Opportunity to help shape and influence the Application Security program.
  • High-visibility role with direct impact across engineering teams.
  • Strong executive support for cybersecurity and technology initiatives.
  • Collaborative, growth-oriented culture.
  • Company-wide focus on innovation and AI-driven transformation.
  • Competitive compensation, benefits, and PTO.
  • Opportunity to make a meaningful impact while helping mature security capabilities across a large development organization.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on public-rest40.bullhornstaffing.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all