> Markdown version of [/jobs/ext/478818-senior-security-engineer-application-cloud-security](https://www.wearedevelopers.com/jobs/ext/478818-senior-security-engineer-application-cloud-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - Application & Cloud Security - **Company:** Acima Leasing - **Location:** Draper, UT, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Static Program Analysis, Code Review, Continuous Integration, DevOps, Identity and Access Management, Intrusion Detection and Prevention, Key Management, Open Web Application Security, Web Application Security, Software Engineering, Data Logging, Enterprise Software Applications, Cloud Platform System, GitHub Copilot, Software Security, Infrastructure as Code (IaC), Cloudformation, Kubernetes, Cybercrime, Terraform, GPT, Devsecops, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d8cebbf746fd060d ## About the Role Do you have experience in Web Application Security Testing?, * 5+ years of experience in Application Security, DevSecOps , Cloud Security, Software Engineering, or related technical disciplines. * Previous hands-on experience as a software developer, DevOps engineer, platform engineer, infrastructure engineer, or similar engineering role. * Experience securing modern CI/CD environments and integrating security into engineering workflows. * Strong experience with Infrastructure as Code ( IaC ), including Terraform, CloudFormation, Kubernetes, Helm, or similar technologies. * Experience with public cloud platforms such as AWS, Azure, or GCP. * Hands-on experience with security tooling such as: SAST, DAST, SCA, etc * Understanding of OWASP Top 10, API security risks, cloud-native security threats, identity security, and modern attack techniques. * Experience investigating and remediating vulnerabilities involving applications, APIs, authentication systems, cloud infrastructure, or software supply chain risks. * Strong understanding of how to leverage AI tools and AI-assisted engineering workflows securely and effectively within day-to-day operations. * Experience using modern AI-assisted development and security platforms such as GitHub Copilot, Claude, ChatGPT, or similar tools to improve engineering productivity, threat analysis, code review, vulnerability research, automation, and operational efficiency. * Ability to evaluate, validate , and securely operationalize AI-generated output within enterprise engineering and cybersecurity environments. * Understand the security implications, risks, and governance considerations associated with AI-assisted software development and modern AI workflows. * Demonstrates a mindset of continuous learning and adaptation as AI rapidly transforms modern software engineering, DevOps, and cybersecurity operations. ## Description You will play a critical role in securing modern cloud-native applications, CI/CD pipelines, APIs, infrastructure, and development ecosystems across the enterprise. The ideal candidate is a cybersecurity-minded engineer who previously worked as a software developer, DevOps engineer, platform engineer, or infrastructure engineer and still possesses strong coding and system-level troubleshooting skills. This role requires someone who can read and understand source code, work closely with engineering teams, threat hunt across modern environments, and help build scalable security capabilities directly into the software development lifecycle. This position will work across Application Security, Cloud Security, and Engineering teams to help secure enterprise applications and cloud infrastructure , operating at scale., * Work directly with software engineers, DevOps engineers, architects, and leadership to identify , prioritize, and remediate security vulnerabilities across applications and cloud environments. * Perform hands-on application security reviews, source code analysis, threat modeling, and architecture reviews for modern applications and APIs. * Build, integrate, automate, and operationalize security controls within modern CI/CD pipelines. * Secure Infrastructure as Code ( IaC ) environments using Terraform, CloudFormation, Kubernetes, and related technologies. * Develop and maintain automated security tooling and workflows across SAST, DAST, SCA, secrets scanning, container security, and cloud security platforms. * Support incident response, threat hunting, forensic investigations, and remediation activities related to application and cloud environments. * Identify and remediate security weaknesses involving APIs, authentication systems, secrets management, cloud infrastructure, containers, and microservices. * Work closely with engineering teams to establish secure-by-default engineering practices and security guardrails. * Assist with implementing and tuning WAF, API security, identity platforms, cloud security tooling, runtime protection, and logging/monitoring capabilities. * Help operationalize modern security practices around: SSDLC, Software supply chain security, Cloud-native security, Threat detection and response * Participate in security investigations involving fraud, insider threats, suspicious application activity, and cloud incidents. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)