> Markdown version of [/jobs/ext/3427758-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/3427758-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Teacher Retirement System of Texas - **Location:** Austin, TX, United States - **Salary:** $108,036.0 - $135,044.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Agile Methodology, Code Review, Cyber Security, Computer Programming, Continuous Delivery, Data Governance, Systems Analysis, Information Technology Audit, Information Systems Security Architecture Professional, Python (Programming Language), Network Segmentation, Open Web Application Security, Secure Coding, Security Information and Event Management, Software Engineering, Scripting, Software Security, Information Technology, Software Coding - **Published:** September 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a7574712c6662d54 ## About the Role * Bachelor's degree from an accredited college or university in Cybersecurity, Information Technology, or a closely related field. * High school diploma or equivalent and additional full-time experience in cybersecurity, information security, systems analysis, programming, computer operations, IT business analysis or related experience may be substituted on an equivalent year-for-year basis., * Must have the ability to maintain the security and integrity of communication infrastructure systems and cybersecurity systems, as defined in Section 117.001(2) of the Texas Business and Commerce Code, and: * Four (4) years of full-time directly related, progressively responsible experience in cybersecurity, information security, systems analysis, programming, computer operations, IT business analysis or related experience. * One (1) year of full-time directly related, progressively responsible experience developing and training employees on security/privacy policies, data handling practices and procedures, and legal obligations or related experience. * One (1) year of full-time directly related, progressively responsible experience conducting IT audits and needs analysis to improve business process solutions. As well as developing and writing IT policies, procedures, and audit responses or related experience. * Experience may be concurrent. * A master's degree or doctoral degree in a closely related field may be substituted on an equivalent year-for-year basis. Required Registration, Certification, or Licensure * Certification as a Certified Information Systems Security Professional (CISSP), or other security related certifications., * Experience with risk management frameworks as it pertains to the National Institute of Standards and Technology. * Experience with various security monitoring tools, network and web assessment tools, and automation techniques. * Basic development or scripting experience and skills. (.Net, Python, and Java are preferred.) * Experience with identifying security issues through code review. * GIAC 500 series or higher certifications, OSCP, or other security related certifications. Knowledge, Skills, and Abilities Knowledge of: * Computer systems and technology limitations, capabilities, and security infrastructures. * Information security systems, controls, methodologies, practices, and regulations, including data encryption and information protection. * National and international laws, regulations, policies, along with ethics as they relate to cybersecurity/privacy. * Organization's risk tolerance and/or risk management approach. * Applicable state and federal laws, statutes, Presidential Directives, executive branch guidelines related to information security or cyber security. * Common security flaws and ways to address them (e.g., OWASP Top 10, CIS Top 18). * Current and emerging cyber technologies. * Agile methodology. * Common code repository and continuous delivery tools. Skills in: * Analyzing complex technical problems and developing workable solutions * Managing multiple conflicting tasks/deadlines. * Effective verbal and written communication of complex technical information. Ability to: * Effectively assess areas of risk associated with information security. * Determine the validity of technology trend data. * Develop policy, plans, and strategies in compliance with laws, regulations, policies, and standards in support of organizational information security assurance. * Establish and maintain harmonious working relationships with co-workers, agency staff, and external contacts. * Work effectively in a professional team environment. ## Description The Application Security Engineer is responsible for performing complex information technology, and cyber security analysis and control work. The incumbent will maintain the security and integrity of communication infrastructure systems and cybersecurity systems, as defined in Section 117.001(2) of the Texas Business and Commerce Code; and ensure the security of TRS applications by implementing and managing application security measures, working closely with the other Information Security team members, the IT department, application development teams, and business technologists to identify and mitigate security risks, develop and implement security protocols, and provide training and support to development staff. WHAT WILL YOU DO: Cybersecurity * Works with application development teams to develop and implement secure coding practices, including coding standards, code reviews, and security-focused testing. * Develops and execute a process for regular application security assessments, including code reviews, threat modeling, and design reviews. * Develops and maintain a library of secure coding resources for application developers. * Develop and implement application security policies and procedures that align with industry standards and best practices. * Provides regular reports to the Information Security Leadership on the status of application security assessments. * Work with application development teams to prioritize and remediate identified vulnerabilities. * Provide training and support to application developers on secure coding practices. * Monitor and enforce compliance with application security policies, procedures, and tooling. * Collaborate with the IT department, Information Security team, and application development teams to design and implement security controls and measures, including access controls, encryption, and network segmentation. Performs related work as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)