> Markdown version of [/jobs/ext/570581-application-security-engineer-remote-us](https://www.wearedevelopers.com/jobs/ext/570581-application-security-engineer-remote-us). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer [Remote-US] - **Company:** Quanata, Llc - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Experienced - **Salary:** $175,000.0 - $215,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Applications Architecture, Software System Penetration Testing, Cloud Computing Security, Mobile Application Software, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, Large Language Models, Prompt Engineering, Software Security, Software Application Programming, Vulnerability Analysis, Programming Languages - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=79f17e4e35cd0ff5 ## About the Role * Associate's degree or equivalent experience required; Bachelor's degree preferred * 4-6+ years of experience in software engineering, including at least 2 years focused on application security * Experience partnering directly with software development teams to improve application security * Knowledge of secure-by-design principles and modern application security practices * Familiarity with OWASP Top 10, ASVS, MASVS, and common application security frameworks * Experience with threat modeling methodologies such as STRIDE, PASTA, or similar approaches * Working knowledge of cloud platforms and modern application architectures * Proficiency in at least one programming language and its security ecosystem * Strong communication skills and the ability to influence technical and non-technical stakeholders * Comfortable operating in a fast-paced environment with shifting priorities, * Security certifications such as CSSLP, GWEB, OSWE, or similar * Experience working in insurance, financial services, healthcare, or other regulated industries * Advanced knowledge of cloud security and application security architecture * Experience with mobile application security, QA testing, or penetration testing * Familiarity with AI technologies, LLM security, or prompt engineering * Experience building scripts or automations to streamline security processes * Active involvement in the security community through conferences, mentoring, presentations, publications, or open-source contributions ## Description We're looking for an Application Security Engineer to help build secure-by-default products and services across Quanata's AI-native insurance technology platform. In this role, you'll partner closely with Product, Engineering, and Security teams to identify risks early, strengthen secure development practices, and ensure our applications are resilient, scalable, and compliant. You'll play a key role in embedding security throughout the software development lifecycle while helping teams move quickly and safely. Your Day-to-Day * Partner with Product and Engineering teams to integrate security into application design and development * Lead threat modeling exercises and identify practical security solutions for complex systems * Conduct secure code reviews, application security assessments, and vulnerability analysis * Develop and implement automated security guardrails across the SDLC * Investigate, prioritize, and drive remediation of application security findings * Promote secure coding practices through training, coaching, and awareness initiatives * Collaborate with Security, Privacy, and Business Assurance teams to support compliance and risk management objectives * Create and maintain security standards, procedures, and best practices that scale across teams ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Same Words, Different Worlds: Who's in Control?](https://www.wearedevelopers.com/videos/2071-same-words-different-worlds-who-s-in-control) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)