Application Security Engineer

Siri InfoSolutions Inc
Jersey City, NJ, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Architectural Patterns Cloud Engineering Cyber Security Continuous Integration Open Web Application Security Power BI Secure Coding Software Vulnerability Management Policy as Code Grafana
+7 more
Software Security Information Technology 3-tier Architectures Serverless Computing Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

The Senior Application Security Engineer serves as a technical and operational leader within the Vulnerability Operations function. This role drives large-scale adoption of application security controls, partnering closely with engineering teams and the Application Security Champion community to ensure secure design, development, and deployment across the enterprise. You will lead strategic control rollouts, guide vulnerability governance, address emerging threat classes, and provide expert escalation support for the most complex AppSec issues. Key Responsibilities: Strategic Leadership & Program Enablement Lead the enterprise-wide operationalization of AppSec controls, ensuring scalable integration across CI/CD pipelines and diverse engineering environments. Partner with the Application Security Champion team to embed secure development practices, coordinate training, share emerging vulnerability insights, and drive decentralized security ownership. Own the tiered security control strategy (Tier 1 3), defining quarterly migration targets and ensuring cross-portfolio alignment. Advanced Vulnerability & Threat Management Act as subject-matter expert for advanced and emerging vulnerability classes (e.g., supply chain risks, AI/ML application threats, container/Serverless misconfigurations, emerging OWASP categories). Lead complex vulnerability triage and remediation efforts; facilitate cross-team deep-dive sessions to drive prioritization and timely mitigation. Conduct proactive threat modeling and security design reviews for high-risk or business-critical applications. Automation & CI/CD Security Architecture Architect scalable CI/CD integrations for SAST, DAST, SCA, and secrets scanning using policy-as-code, automated gating, and risk-based controls. Implement and optimize Tier 3 merge-prevention and build-failure gates, ensuring engineering teams meet strict compliance requirements. Develop reusable automation frameworks, scanning templates, and pipeline modules to accelerate secure software delivery. Governance, Reporting & Stakeholder Engagement Design and maintain KPIs, scorecards, and compliance dashboards using analytics platforms (Power BI, Grafana, or equivalent). Lead risk review forums, document mitigations, publish weekly risk register updates, and deliver executive-level insights on trends, gaps, and emerging threats. Oversee quarterly migration planning, dependency tracking, and cross-team alignment on AppSec program objectives. Mentor AppSec Specialists and upskill partner engineering teams on tools, governance workflows, and emerging security techniques. Emerging Vulnerabilities & Continuous Improvement Stay current with modern vulnerability trends (e.g., supply chain risks, API threats, cloud-native issues). Evaluate tool outputs, identify false positives, and provide actionable remediation guidance. Recommend improvements to scanning processes, workflows, and onboarding procedures. Required Qualifications & Skills

Requirements

Bachelor’s or Master’s in Computer Science, Cybersecurity, or related field. 7+ years of experience in Application Security engineering, vulnerability management, or secure development. Expertise in advanced AppSec concepts: secure design patterns, threat modeling, exploit analysis, and remediation strategy for modern architectures (microservices, APIs, cloud-native). Proven experience leading CI/CD-integrated security automation (SAST, DAST, SCA, secrets scanning, IaC scanning). Strong track record of working with engineering organizations and AppSec Champions to drive program adoption. Demonstrated ability to interpret complex vulnerability trends, emerging threats, and zero-day risk scenarios. Excellent communication, executive presentation skills, and ability to influence senior technical leaders.

About the company

Job Description: What We’re Doing Lockheed Martin is shaping the future of defense through cutting edge radar and missile defense technologies, and we want you to help write the n…, © 2026 Careerjet All rights reserved

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:07 min

Transitioning architecture to microservices at Netflix

Steve Upton Steve Upton · WWC 2022

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

10:40 min

Visualizing Prometheus open metrics using custom Grafana dashboards

Stijn Polfliet · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

3:38 min

Shifting from monolithic architectures to microservices and containers

Markus Kett Markus Kett · WWC 2022

Videos

See all

Related articles

See all