about 3 hours ago
Senior Application Security Engineer
Remote - USA
$130,100-$187,000 / year
full-timesenior RemoteCybersecurity
Tech Stack
Description
In this role, you will integrate security into every phase of the software development lifecycle, conduct comprehensive security reviews, and partner with engineering teams to build defensible architectures. You'll own security architecture and secure coding practices while mentoring junior engineers and acting as a technical liaison across teams.
Requirements
- Proven delivery in application security engineering roles, ideally in cloud-native environments with modern development practices.
- Hands-on experience with security testing tools (SAST, DAST, SCA, IAST) and working knowledge of security automation in CI/CD pipelines.
- Strong programming skills in Python, Go, Java, or JavaScript/TypeScript; proficiency with Git, Linux, and modern development frameworks.
- Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design.
- Experience with threat modeling frameworks (STRIDE, PASTA, LINDDUN) and security architecture review processes.
- Comfortable investigating application logs, tracing security events, and contributing to incident analysis workflows.
- Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams.
- Strong written communication and documentation skills and being able to convey complex security concepts clearly.
- Background with securing modern application architectures including microservices, containers, and cloud-native applications.
Responsibilities
- Lead threat modeling and security architecture reviews with engineering teams by translating security risks into development actions.
- Architect, build, and maintain security tooling and integrations that enable secure development workflows (e.g., SAST, DAST, SCA, IAST tools).
- Collaborate with Engineering, DevOps, and Platform teams to build scalable security controls via Infrastructure-as-Code and secure CI/CD pipelines.
- Design and deploy automated security testing frameworks to identify vulnerabilities early in the development process.
- Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
- Mentor and support junior engineers on secure coding practices, security architecture, and security tooling integrations.
- Evaluate and uplift application security tooling across commercial and open-source capabilities by focusing on scale, efficiency, and precision.
- Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.
- Partner with engineering teams to implement and maintain security controls across applications and services.
- Stay current with emerging AI/ML security threats, evaluating them for business applicability and integration.
0 views 0 saves 0 applications