Application Security Engineer

Insight Global
Philadelphia, PA, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Engineering Continuous Integration OAuth OpenID Open Web Application Security Fortify (Software) Security Assertion Markup Language (SAML) Secure Coding Software Engineering
+7 more
Software Security Veracode GWAPT Kubernetes Cyber Warfare Docker Vulnerability Analysis

Job description

Insight Global is seeking an Application Security Engineer to join a growing Cyber Defense & Engineering team. This individual will play a key role in building and maturing an enterprise-wide Application Security program as the organization continues its cloud modernization efforts.

This is a highly visible, hands-on position focused on establishing security standards, implementing scalable AppSec practices, and partnering directly with development teams to improve application security across the organization. The ideal candidate enjoys building processes from the ground up and can effectively bridge the gap between security and engineering teams.

Requirements

4+ years of experience in Application Security, Software Engineering, Cloud Engineering, or a related field. Strong understanding of application security principles, secure development practices, and modern attack vectors. Experience with threat modeling methodologies such as STRIDE, PASTA, or similar. Knowledge of OWASP Top 10, OWASP ASVS, and common web/API security vulnerabilities. Experience integrating security controls and testing into CI/CD environments. Understanding of OAuth 2.0, OIDC, SAML, and modern authentication patterns. Familiarity with containerized and cloud-native environments (Docker, Kubernetes, etc.). Preferred Qualifications Experience building or maturing an Application Security program. Experience with tools such as Fortify, Veracode, or Wiz. Azure and/or AWS cloud security experience. Exposure to API security testing, WAFs, and runtime application protection. Security certifications such as CISSP, OSCP, OSWE, GPEN, or GWAPT.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

Videos

See all

Related articles

See all