Senior Application Security Engineer
New
Q
Quanata, LLCInsurance technology
You may work from anywhere you like in the U.S, excluding U.S. territories., Core meeting hours are 9AM–2PM Pacific time.Full-TimeSenior
Salary232,000 - 379,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 6–8 years of experience in application security or full-stack development with security expertise.
- Required Skills
- Node.jsPythonJavascriptTypeScript
Requirements
- Have a bachelor’s degree or equivalent relevant experience.
- Have 6–8 years of experience in application security or full-stack development with security expertise.
- Understand secure coding practices in Python, JavaScript/TypeScript, and Node.js.
- Understand web standards and application risks, including the OWASP Top 10 for web and GenAI LLM, API security, and SSRF.
- Have experience with code-scanning tools such as CodeQL, Wiz, SonarQube, or Snyk.
- Be comfortable reading and debugging complex codebases across the technology stack.
- Communicate clearly and guide engineers at all levels.
Responsibilities
- Partner with a product portfolio to manage product security, emphasizing AI/ML automation, security consulting, and cross-functional collaboration.
- Lead security design reviews and threat modeling for APIs, web features, and service integrations.
- Integrate SAST, SCA, and DAST tooling into CI/CD pipelines and developer workflows.
- Review source code and deployment configurations to identify vulnerabilities, and work with developers to triage, remediate, and validate findings.
- Maintain application security guidance and contribute to security awareness and enablement.
- Develop and deploy application security automation and integrations, including ASVS scanning and Burp Suite Enterprise.
- Support application security integration reviews, SaaS security assessments, and open-source software reviews.
- Participate in cross-functional incident response and remediation planning.
View Full Description & ApplyYou'll be redirected to the employer's site