> Markdown version of [/jobs/ext/559672-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/559672-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Virtru Corporation - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $180,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Amazon Web Services, Software System Penetration Testing, User Authentication, Static Program Analysis, Node.Js, Open Source Technology, Systems Development Life Cycle, Reliability Engineering, Secure Coding, Software Vulnerability Management, Data Logging, Software Security, Kubernetes, Cybercrime, Nessus, Asynchronous Programming, Web Architecture, Qualys, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cc5d6ed45d0d93cc ## About the Role Do you have experience in Video conferences (communication methods)?, * 4+ years experience in secure development or application security. * Deep knowledge of security concepts such as authentication, web architecture, etc. * Experience with Nodejs, Go, etc. * Experience running bug-bounty, penetration testing, vulnerability scanning programs. * Experience setting up and maintaining SAST, DAST, IAST and SCA tooling * Experience using assessment tools such as Burp, ZAP, Qualys, Nessus, etc. * Experience building and maintaining WAF solutions. * Familiarity with industry security practices, standards, and regulations such as FedRAMP, SOC2, HIPAA, etc. a plus. * Familiarity with GCP/AWS and Kubernetes infrastructure security a plus. * Self-motivated and goal driven, able to find what needs to be done and do it. Virtruvian qualities that will set you up for success: * Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence * Strong sense of urgency with an action-oriented mindset * Able to collaborate and adapt to shifting priorities as business needs evolve * Comfortable with asynchronous communication including slack, email, zoom, etc. ## Description Here at Virtru you'll join an innovative product security team that is helping secure some of the world's most important information. Our platform, built on an open source core, functions in a wide range of threat models. As an application security engineer you will help our engineering teams maintain and develop our product, and directly have impact in a security centric company and product. An ideal candidate is prepared to operate in a public and open source form, in addition to being able to review complex systems and product requirements. You should have a strong foundation in the fundamentals of cryptography, and be able to talk and collaborate with development teams. Our applications are primarily built in Go and Javascript. We use a range of security tools, and aggressively automate where we can (even if we have to code and build it). If you are excited rather than scared by highly technical problems, we are offering a security role where you can learn and grow while having direct impact in continuing to harden a security critical mission. As an Application Security Engineer, your responsibilities will include: * Security Engineering * + Collaborate with development teams, Site Reliability Engineering, and other stakeholders to strengthen the adoption of security best practices throughout the SDLC. + Independently identify security improvements and implement them. * Vulnerability Management: * + Implement, manage, and automate vulnerability management processes. + Prioritize and remediate vulnerabilities discovered through internal scans, penetration tests, and bug bounties. * Security Assessments * + Conduct threat modeling, code audits, design reviews with engineers to ensure effective and secure development. + Collaborate in providing actionable recommendations to find workable solutions. * Threat Hunting: * + Establish a threat hunting capability and automate where appropriate. + Enhance logging capabilities related to security events. * Security Tools Integration and Management: * + Integrate and manage dynamic and static code analysis tools. + Ensure operation of security tools within the development pipeline. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Building AI Applications with LangChain and Node.js](https://www.wearedevelopers.com/videos/1512-building-ai-applications-with-langchain-and-node-js) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)