> Markdown version of [/jobs/ext/540127-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/540127-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Magnum Hunt - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** ASP.NET, Java (Programming Language), Microsoft Windows, Application Programming Interfaces (APIs), Agile Methodology, Ajax (Programming Language), Big Data, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing, Code Review, Encodings, Databases, Cross-Site Request Forgery, Software Debugging, Linux, Perl (Programming Language), Fiddler (Software), JSON, Python (Programming Language), Microsoft Office, Microsoft SQL Server, Model View Controller (MVC), Object-Oriented Software Development, Systems Development Life Cycle, Reverse Engineering, Secure Coding, Web Application Security, Service-Oriented Architecture, Software Engineering, SQL Injection, Web Applications, Web Testing, Extensible Markup Language (XML), Scripting, Transport Layer Security, Software Security, Cross-Site Scripting (XSS), Mitmproxy - **Published:** June 15, 2026 - **Apply:** http://www.magnumhunt.com/Apply?JobID=769 ## About the Role * 5+ years of hands-on application security experience. * Hands-on development experience and thorough understanding of object-oriented programming, preferably Java, C#, ASP.NET * Advanced knowledge of web application technologies, MVC, Ajax, XML, JSON, SOA, SSL, web-related protocols and services. * Intermediate knowledge of MS SQL. Basic knowledge of other commonly-used DBMS. * Experience with cloud and "big data" storage, databases, and APIs * Ability to identify security vulnerabilities from source code reviews and testing. * Knowledge of encryption technologies, secure communications, and secure credentials management. * Advanced experience with at least one scripting language (e.g.: Perl, Python) * Intermediate proficiency with C/C++ or Java. Experience with lower-level languages (Assembly), debug and reverse-engineering tools (IDA, etc.) is a plus. * Advanced knowledge of common application vulnerabilities, (e.g.: XSS, CSRF, SQL injection, cookie/header/encoding manipulation, input/output validation, session replay). * Intimate familiarity with web application testing tools (eg: Burp, Parox, Fiddler, mitmproxy, Havij, netcat). Ability to write proof-of-concept exploits is a big plus. * Ability to define application security requirements and build secure web application solutions. * Advanced written and verbal communication skills including ability to present technical subjects to non-technical audiences. * Strong work ethic, attention to detail, and organizational skills. * Ability to multi-task and manage priorities in a fast-paced environment. * Ability to collaborate in a team and work independently. * Conceptual understanding of software development principles and SDLC models, Agile experience is a plus. * Intermediate proficiency with the Microsoft Office suite. * Windows and Linux operating systems knowledge at advanced user level. ## Description * Identify risks and areas of exposure in applications developed and/or used by BlackLine. * Perform security reviews of source code, stored procedures, and server/service configurations. * Define and document application security requirements for BlackLine applications. * Oversee development of security components throughout all stages of the SDLC. * Perform manual and automated security testing of BlackLine applications. * Monitor application logs and audit trails. * Monitor industry trends and threat landscape and recommend necessary controls or countermeasures. * Educate developers on secure coding techniques and security best practices. * Participate in development of security policies, standards, and processes. * Participate in incident handling and perform application-related forensics activities. * Perform other duties as assigned ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Building Multi-Tenant ASP.NET Core Applications: Best Practices and Real-World Solutions](https://www.wearedevelopers.com/videos/1552-building-multi-tenant-asp-net-core-applications-best-practices-and-real-world-solutions) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Developing ASP.NET Core Microservices with Dapr: A practical guide](https://www.wearedevelopers.com/videos/1528-developing-asp-net-core-microservices-with-dapr-a-practical-guide) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)