> Markdown version of [/jobs/ext/569431-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/569431-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Arcadia Inc. - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $131,250.0 - $235,156.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Software as a Service, Cloud Engineering, Cyber Security, Continuous Integration, Github, Identity and Access Management, Systems Development Life Cycle, Web Application Security, Software Vulnerability Management, Delivery Pipeline, Software Security, GWAPT, Containerization, Gitlab-ci, Kubernetes, Graphql, Checkmarx, Docker, Jenkins, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7038eb0c38493c2c ## About the Role Do you have experience in Web Application Security Testing?, We are seeking a technically hands-on Application Security Engineer to join the Information Security team. This individual will own the vulnerability management lifecycle across our SAST, DAST, and SCA tooling, integrate security automation into the CI/CD pipeline, perform threat modeling of product and engineering designs, and serve as a trusted advisor to our 300+ person engineering organization. The ideal candidate is a builder who would rather automate a finding than file a ticket, and who can explain a critical vulnerability to a junior developer without making them feel two inches tall., * 3-5 years of dedicated Application Security experience in a SaaS or cloud-native environment. * Hands-on proficiency with at least two of the following: SAST, DAST, SCA, or CSPM tooling (e.g., Snyk, Checkmarx, Semgrep, Wiz). * Strong working knowledge of CI/CD pipelines (e.g., GitHub Actions, Jenkins, GitLab CI) and the ability to write and maintain pipeline integrations. * Experience with container security (Docker, Kubernetes) and API security patterns (REST, GraphQL). * Demonstrated ability to communicate technical risk to non-security engineers in a way that drives action, not anxiety. Nice-to-haves: * Experience standing up or maturing a Security Champions program. * Familiarity with cloud-native AWS security services (GuardDuty, Security Hub, IAM Access Analyzer). * Exposure to threat modeling frameworks (STRIDE, PASTA, or lightweight equivalents). * Relevant certifications (OSCP, GWAPT, CSSLP) - valued but not required. ## Description * Own the end-to-end vulnerability management lifecycle: triage, prioritize, and drive remediation of findings from SAST, DAST, and SCA tooling in partnership with engineering squads. * Maintain, optimize, and extend security tooling integrations within the CI/CD pipeline with the goal of automating everything that can be automated. * Launch and run a Security Champions program, including workshops and office hours, to embed security knowledge directly into development teams across multiple geographies. * Act as the application-layer subject matter expert during security incidents, supporting triage, root cause analysis, and remediation. * Partner with Product and Engineering leadership to introduce security touchpoints earlier in the SDLC, including threat modeling and design review processes. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)