Sr. Application Security Engineer

New
J
JobgetherApplication Security
Based in United StatesFull-TimeSenior
Salary130,000 - 190,000 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field.
Required Skills
AWSPythonJavaGo

Requirements

  • Have 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field.
  • Demonstrate senior-level ownership of Application Security initiatives and vulnerability remediation.
  • Have hands-on coding and secure code review experience with Java, Python, and Go.
  • Be able to read, debug, and reason about production application code and communicate findings to software engineers.
  • Be able to reproduce vulnerabilities, trace root causes, assess exploitability and reachability, and validate remediation.
  • Have hands-on experience with SAST, DAST, and SCA tools and integrating security testing into engineering workflows.
  • Have strong knowledge of software dependency and supply-chain security.
  • Have experience prioritizing vulnerabilities using application and business context, not scanner severity alone.
  • Understand the OWASP Top 10 and OWASP API Security risks.
  • Have experience with threat modeling using STRIDE, PASTA, or similar methodologies.
  • Have experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
  • Application and API penetration-testing experience is preferred.
  • Familiarity with PCI-DSS application security requirements and experience building or leading a Security Champions program are preferred.
  • OSCP, GWEB, CSSLP, or a similar technical security certification is preferred.

Responsibilities

  • Perform hands-on security analysis of applications, APIs, services, and supporting components.
  • Conduct secure code reviews across Java, Python, and Go codebases, identifying root causes and practical remediation paths.
  • Reproduce and validate vulnerabilities, assessing exploitability, reachability, exposure, and business context.
  • Own vulnerability remediation from discovery through prioritization, remediation, retesting, and closure.
  • Develop reusable secure coding patterns, preventative controls, and automation to reduce recurring vulnerabilities.
  • Mature security gates and review checkpoints across architecture, design, sprint, and release processes.
  • Integrate preventative security controls into developer workflows and CI/CD pipelines.
  • Configure, operate, and tune SAST, DAST, and SCA tooling.
  • Threat-model new features and significant architectural changes using STRIDE, PASTA, or equivalent methodologies.
  • Partner with Engineering teams to provide remediation guidance, secure-coding training, and security standards.
View Full Description & ApplyYou'll be redirected to the employer's site
130,000 - 190,000 USD per year
Apply Now