> Markdown version of [/jobs/ext/3096053-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3096053-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Corporate Brokers, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Agile Methodology, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Burp Suite, C Sharp (Programming Language), Cyber Security, Open Web Application Security, Scrum Methodology, Systems Development Life Cycle, Secure Coding, Software Engineering, Data Streaming, Wireshark, Software Vulnerability Management, Web Applications, Enterprise Software Applications, Software Security, SOAPAPI, Metasploit, Nessus, Api Gateway, Devsecops, Qualys, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 26, 2026 - **Apply:** https://public-rest40.bullhornstaffing.com/rest-services/BJ529/query/JobBoardPost?where=id=19596&fields=id,title,publishedCategory(id,name),address(city,state),employmentType,dateLastPublished,publicDescription,isOpen,isPublic,isDeleted ## About the Role * 5+ years of experience in Application Security, Secure Software Development, DevSecOps, or a related cybersecurity discipline. * Hands-on experience performing threat modeling and security architecture reviews. * Strong understanding of vulnerability management and remediation processes. * Experience supporting security testing programs utilizing: + SAST + DAST + SCA * Knowledge of OWASP Top 10, SANS/CWE vulnerabilities, and secure coding principles. * Experience partnering directly with software development teams. * Understanding of secure SDLC methodologies and DevSecOps practices. * Ability to analyze source code and identify security concerns. * Strong verbal and written communication skills. Preferred Qualifications * Experience working in C#/.NET or Java development environments. * Previous experience as a software engineer who transitioned into security. * Experience securing APIs, web applications, and enterprise software platforms. * Familiarity with security tools such as: + Burp Suite + OWASP ZAP + Wireshark + Nessus + Qualys + Metasploit * Experience with WAF technologies, API security platforms, and API gateways. * Exposure to Azure and/or AWS security controls. * Knowledge of security frameworks such as NIST, ISO 27001, OWASP SAMM, Microsoft SDL, or BSIMM. * Experience integrating security controls into CI/CD pipelines., The ideal candidate is a security-first professional who understands how modern applications are built and can effectively influence engineering teams. While familiarity with software development is valuable, we are prioritizing deep Application Security expertise, including threat modeling, vulnerability management, security testing, and secure SDLC practices. ## Description Our client is seeking an experienced Application Security Engineer to serve as a trusted security advisor embedded within our Agile development organization. This role will partner closely with software engineering teams to integrate security throughout the Software Development Lifecycle (SDLC), helping ensure applications and APIs are designed, built, and deployed securely. This individual will play a critical role in advancing application security practices, driving DevSecOps maturity, and helping development teams proactively identify and remediate security risks. The ideal candidate combines strong application security expertise with the ability to collaborate effectively with developers and technical stakeholders. About the Team * Support approximately 100 software engineers across multiple engineering teams. * Partner directly with 6 Scrum teams in an Agile environment. * Join a highly visible Application Security function with significant opportunity to influence processes and strategy. * Work primarily within a Microsoft-based technology ecosystem featuring C#, .NET Framework, SOAP services, APIs, and enterprise applications. * Help drive the evolution and maturity of a growing DevSecOps and Application Security program., * Serve as the primary Application Security advisor for development teams. * Embed security best practices throughout the Software Development Lifecycle (SDLC). * Conduct threat modeling exercises and security risk assessments for applications and APIs. * Review application architectures, designs, data flows, and new feature implementations from a security perspective. * Validate, triage, and prioritize vulnerabilities identified through: + SAST tools + DAST tools + Software Composition Analysis (SCA) + Vulnerability assessments + Penetration testing activities * Provide remediation guidance and work directly with development teams to resolve security findings. * Participate in sprint planning sessions and Agile ceremonies to ensure security requirements are incorporated early in the development process. * Support the deployment, tuning, and ongoing effectiveness of application security testing programs. * Promote secure coding practices and mentor engineering teams on application security concepts. * Assist in developing and maturing DevSecOps processes, standards, and automation capabilities. * Translate technical security risks into actionable business recommendations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)