Staff Application Security Engineer
New
J
JobgetherApplication security
This is a remote opportunity within the United StatesFull-TimeStaff
SalaryBase salary range of $182,800–$215,000 USD
Apply NowOpens the employer's application page
Job Details
- Experience
- Significant professional experience in application security, security engineering, software engineering, or a closely related discipline
- Required Skills
- DockerNode.jsPythonJavaKubernetesRubyC#
Requirements
- Significant professional experience in application security, security engineering, software engineering, or a closely related discipline, with demonstrated ownership of security outcomes.
- Advanced proficiency in at least one programming language such as Ruby, Java, Python, C#, or Node.js.
- Strong hands-on experience managing SIEM platforms and developing detection and alerting strategies.
- Deep understanding of cloud environments and container technologies, including Docker and Kubernetes.
- Experience implementing automated container vulnerability management.
- Extensive experience with SAST, DAST, and IAST methodologies and tools, including manually validating security findings.
- Strong knowledge of the OWASP Top 10, MITRE Top 25, and secure software development practices.
- Experience conducting security architecture, code, infrastructure, and application reviews and recommending remediation.
- Experience with cloud security concepts and compliance frameworks such as SOC 2 and PCI.
- Ability to mentor others, advocate for security best practices, and influence teams without relying solely on formal authority.
Responsibilities
- Own and continuously improve the organization's SIEM through configuration, tuning, monitoring, and effective threat-detection alerts.
- Conduct security architecture reviews, code reviews, and infrastructure configuration assessments, and recommend remediation strategies.
- Perform targeted penetration testing of web and mobile applications, manually validating vulnerabilities and investigating their causes.
- Build and optimize vulnerability management processes and CI/CD pipelines across container and application delivery environments.
- Partner with software development and infrastructure teams to promote secure coding, prioritize remediation, and resolve security issues.
- Develop security frameworks, tooling, and engineering standards that make security requirements scalable and actionable.
- Contribute to incident response and forensic investigations using technical evidence and business context.
- Monitor emerging threats and translate them into practical recommendations for engineering teams.
- Develop and support security awareness and training initiatives.
- Mentor others and advise stakeholders across engineering, infrastructure, and security.
View Full Description & ApplyYou'll be redirected to the employer's site