> Markdown version of [/jobs/ext/736651-associate-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/736651-associate-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Application Security Engineer - **Company:** North American - **Location:** United States (Remote available) - **Salary:** $90,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** HTML, JavaScript (Programming Language), Application Programming Interfaces (APIs), Amazon Web Services, Data Analysis, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Cross-Origin Resource Sharing (Ajax Programming), DevOps, Domain Name System (DNS), Python (Programming Language), Kali Linux, Log Analysis, Network Protocols, Nmap, Open Web Application Security, Windows PowerShell, Security Information and Event Management, TCP/IP, Software Vulnerability Management, Web Applications, Web Application Frameworks, Scripting, Google Cloud, Grafana, Software Security, Git, Kubernetes, Information Technology, Metasploit, Web Technologies, Terraform, Burpsuite, Docker, Vulnerability Analysis - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fcbcb8bda5935b59 ## About the Role Do you have a Bachelor's degree?, * Bachelor of Science in Cybersecurity, Computer Science, or an allied technical discipline, complemented by equivalent professional expertise. * Experience with web vulnerabilities, web attack paths, and web vulnerability remediation in modern web frameworks * Experience with cloud platforms (AWS, Azure, GCP) and their native security tools * Experience with security testing tools such as BurpSuite, nmap, Metasploit, and security testing distributions such as Kali Linux * Experience with data analysis and SIEM tools (e.g., Grafana, Opensearch, CS NextGen SIEM) for log analysis and monitoring * Strong networking fundamentals and familiarity with network protocols (HTTP/HTTPS, TCP/IP, DNS) and web technologies (HTML, JavaScript, APIs) * Basic scripting knowledge using Python, Bash, and PowerShell * Comfortable using terminals, scripting, and automation for WAF automation use-cases * Ability to translate complex technical vulnerabilities, threat impact, and remediation urgency into actionable, risk-prioritized reports for both technical and non-technical stakeholders How to stand out (preferred): * Relevant industry certifications and qualifications (e.g., CompTIA Security+, CEH, OSCP, or equivalent) are a plus * Experience executing penetration testing aligned with OWASP Top 10 standards and modern browser security baselines * Experience partnering with engineering teams on vulnerability remediation, including CSP rules, secure CORS origins, and HSTS enforcement * Experience developing novel testing methodologies to bypass or harden application-layer defenses * Familiarity with DevOps tools (e.g., Docker, Kubernetes, Terraform, git) and CI/CD pipelines * Ability to refine automated security tools to reduce false positives and ensure continuous monitoring of critical web assets * Experience conducting security research and threat intelligence to advance organizational defenses * Knowledge of hardened security configurations including CSP rules, secure CORS origins, and strict HSTS enforcement ## Description Join our security team as an Associate Application Security Engineer and play a hands-on role in defending cloud infrastructure, networks, and modern web applications using enterprise-level tools. In this role, you will develop your expertise in vulnerability assessment and threat research while collaborating closely with engineering teams to drive timely and effective remediation. You'll leverage automation, scripting, and data analysis to scale security testing, reduce risk, and continuously monitor critical assets. This is an excellent opportunity for an early-career security professional looking to grow their skills in a fast-paced, collaborative environment. What you'll do: * Application protection and defense, recommend configuration changes, adjustments and enhancements for web application protection controls and monitor for and report on abnormal events. * Coordinate with application and infrastructure teams to ensure effective protections and responses. * Conduct application assessments and security tests together with the testing team. Maintain, add, enhance, and expand the scope of application assessments and penetration tests. * Use augmented instruments and tools for application assessments and evaluations. * Document, triage and track vulnerabilities and exposures as well as assisting and advising on remediation. * Identify and track risks and exposures, create leads for assessments * Document and maintain operational processes and procedures. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [NoLoJS - Avoiding JavaScript Cruft with HTML and CSS - Aaron T. Grogg](https://www.wearedevelopers.com/videos/1806-nolojs-avoiding-javascript-cruft-with-html-and-css-aaron-t-grogg) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)