Sr. Application Security Engineer
New
J
JobgetherApplication Security
Based in United StatesFull-TimeSenior
Salary130,000 - 190,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field.
- Required Skills
- AWSPythonJavaGo
Requirements
- Have 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field.
- Demonstrate senior-level ownership of Application Security initiatives and vulnerability remediation.
- Have hands-on coding and secure code review experience with Java, Python, and Go.
- Be able to read, debug, and reason about production application code and communicate findings to software engineers.
- Be able to reproduce vulnerabilities, trace root causes, assess exploitability and reachability, and validate remediation.
- Have hands-on experience with SAST, DAST, and SCA tools and integrating security testing into engineering workflows.
- Have strong knowledge of software dependency and supply-chain security.
- Have experience prioritizing vulnerabilities using application and business context, not scanner severity alone.
- Understand the OWASP Top 10 and OWASP API Security risks.
- Have experience with threat modeling using STRIDE, PASTA, or similar methodologies.
- Have experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
- Application and API penetration-testing experience is preferred.
- Familiarity with PCI-DSS application security requirements and experience building or leading a Security Champions program are preferred.
- OSCP, GWEB, CSSLP, or a similar technical security certification is preferred.
Responsibilities
- Perform hands-on security analysis of applications, APIs, services, and supporting components.
- Conduct secure code reviews across Java, Python, and Go codebases, identifying root causes and practical remediation paths.
- Reproduce and validate vulnerabilities, assessing exploitability, reachability, exposure, and business context.
- Own vulnerability remediation from discovery through prioritization, remediation, retesting, and closure.
- Develop reusable secure coding patterns, preventative controls, and automation to reduce recurring vulnerabilities.
- Mature security gates and review checkpoints across architecture, design, sprint, and release processes.
- Integrate preventative security controls into developer workflows and CI/CD pipelines.
- Configure, operate, and tune SAST, DAST, and SCA tooling.
- Threat-model new features and significant architectural changes using STRIDE, PASTA, or equivalent methodologies.
- Partner with Engineering teams to provide remediation guidance, secure-coding training, and security standards.
View Full Description & ApplyYou'll be redirected to the employer's site