> Markdown version of [/jobs/ext/576047-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/576047-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** Self Esteem Brands, LLC - **Location:** Boca Raton, FL, United States (Remote available) - **Experience:** Experienced - **Contract:** Franchise - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Static Program Analysis, Code Review, CompTIA Security+, Information Systems, Continuous Integration, DevOps, Github, Infrastructure as a Service (IaaS), Open Web Application Security, Platform as a Service (PAAS), Systems Development Life Cycle, Application Data, Secure Coding, Web Application Security, Software Engineering, Cloud Platform System, Software Security, GWAPT, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2d2c654c2f10cde1 ## About the Role Do you have experience in Web Application Security Testing?, * Bachelor's degree in Computer Science, Information Systems, Engineering, or a related field * 3-5 years of experience in application security, security engineering, or software engineering with a strong security focus * Hands-on experience performing code reviews and application security testing across modern languages, frameworks, and APIs * Experience working with application security tools such as SAST, DAST, and dependency scanning (e.g., GitHub Dependabot or similar) * Strong understanding of OWASP Top 10 , secure coding principles, authentication/authorization, and API security * Practical experience supporting applications running in AWS and/or Azure cloud environments * Familiarity with CI/CD pipelines, DevOps workflows, and DevSecOps concepts * Ability to communicate security risks and remediation guidance clearly to developers and non-security stakeholders * Strong analytical skills with the ability to balance security risk with delivery velocity Preferred certifications include: Security+, CSSLP, GWAPT, GWEB, CEH, or other application security-focused certifications ## Description The Application Security Engineer will report to the Staff Security Engineer and will be responsible for advancing application security capabilities as part of a DevSecOps operating model. This role focuses on embedding security controls, automation, and secure development practices directly into the software delivery lifecycle for cloud-based applications. The Application Security Engineer will partner closely with software engineering, DevOps, and cloud teams to shift security left, improve vulnerability detection and remediation workflows, and reduce risk without slowing delivery. This position emphasizes hands-on application security engineering, security tooling integration, and developer enablement across applications deployed in AWS and Azure environments., * Embed application security practices into all phases of the software development lifecycle (SDLC) , from design through deployment and maintenance * Perform application security assessments including static code analysis (SAST), dynamic testing (DAST), and software composition analysis (SCA) * Develop and maintain threat models for critical systems and applications, collaborating with engineering teams to identify threats, assess risk, and drive remediation efforts * Promote secure coding practices and contribute to secure development standards aligned with OWASP and industry best practices, * Partner with engineering and DevOps teams to integrate security tooling into CI/CD pipelines , enabling automated and repeatable security testing * Analyze and manage vulnerability findings from tools such as GitHub Dependabot , application scanners, and cloud-native security services * Help tune security tooling to reduce false positives and improve signal quality for development teams * Support the adoption of security automation to improve consistency, efficiency, and scalability across application environments Cloud & Platform Security Collaboration * Assist in securing applications deployed across AWS and Azure , including workloads running on IaaS, PaaS, and container-based platforms * Identify risks to the confidentiality, integrity, and availability of application data hosted in cloud-based environments * Collaborate with cloud and platform security engineers to ensure application security controls align with broader cloud security architecture Risk Management, Monitoring & Response * Triage, prioritize, and track remediation of application vulnerabilities based on risk and business impact * Assist in security investigations involving application vulnerabilities or security events * Participate in periodic reviews of application security controls to validate effectiveness and compliance with organizational standards Collaboration & Continuous Improvement * Act as a security partner to engineering teams by providing guidance, education, and actionable recommendations * Contribute to the continuous improvement of application security processes, standards, and metrics * Support governance, risk management, and compliance initiatives as they relate to application security ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)