7h ago
New
$130,000 – $190,000/yr

Sr. Application Security Engineer

United StatesUnited StatesRemoteFull-timesenior
EngineeringSecurity Engineer
3 views0 saves0 applied

Quick Summary

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Application Security Engineer based in United States.

Technical Tools
EngineeringSecurity Engineer

This is a highly technical Application Security role focused on protecting software products, APIs, and cloud-native applications throughout the development lifecycle.
You will work hands-on with Java, Python, and Go codebases to identify vulnerabilities, trace root causes, assess exploitability, and guide secure remediation.
The role bridges Information Security and Engineering, giving you significant ownership while keeping you deeply connected to software development teams.
You will help strengthen the Secure SDLC through security gates, threat modeling, automated controls, and developer-focused security workflows.
The position also covers SAST, DAST, SCA, API security, dependency risk, cloud-native architectures, and hands-on vulnerability validation.
Beyond addressing individual findings, you will build preventative controls and secure coding practices that reduce recurring vulnerability classes.
This opportunity is ideal for an experienced Application Security professional who enjoys solving complex technical problems and influencing engineering teams through practical security expertise.

As a Sr. Application Security Engineer, you will serve as a hands-on technical authority for application security, partnering closely with Engineering and Security teams to identify risks, drive remediation, and embed security into development practices.

  • Perform hands-on security analysis of applications, APIs, services, and supporting components.
  • Conduct secure code reviews across Java, Python, and Go codebases, identifying root causes and practical remediation paths.
  • Reproduce and validate vulnerabilities independently, assessing exploitability, reachability, exposure, data sensitivity, business criticality, and compensating controls.
  • Own vulnerability remediation from discovery through prioritization, remediation, retesting, and closure.
  • Maintain remediation SLAs and escalate unresolved Critical and High findings when appropriate.
  • Develop reusable secure coding patterns, preventative controls, and automation to reduce recurring vulnerabilities.
  • Mature security gates and review checkpoints across architecture, design, sprint, and release processes.
  • Integrate preventative security controls into developer workflows and CI/CD pipelines.
  • Configure, operate, and tune SAST, DAST, and SCA tooling to deliver actionable security feedback.
  • Assess software dependency and supply-chain risks using application context, reachability, exploitability, and remediation options.
  • Threat-model new features and significant architectural changes using STRIDE, PASTA, or equivalent methodologies.
  • Review authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, data flows, trust boundaries, cryptographic controls, and abuse scenarios.
  • Evaluate application security across AWS, Kubernetes/EKS, containers, Linux/Ubuntu, distributed services, and cloud-native architectures.
  • Partner with Engineering as a technical advisor, providing clear and actionable remediation guidance.
  • Deliver secure-coding guidance and training based on real vulnerabilities and recurring security patterns.
  • Help establish and mature a Security Champions program across development teams.
  • Create security runbooks, standards, and reusable development patterns that teams can apply independently.
  • Validate application and API vulnerabilities through hands-on testing and coordinate external penetration-testing engagements.
  • Drive first-year improvements in vulnerability remediation, threat modeling, dependency security, secure development practices, and the overall effectiveness of the Application Security function.

Requirements

~2 min read

The role requires deep Application Security expertise combined with strong software engineering capabilities, hands-on vulnerability analysis, and the ability to collaborate effectively with technical and engineering leadership.

  • 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related field.
  • Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.
  • Strong hands-on coding and secure code review experience with Java, Python, and Go.
  • Ability to read, debug, and reason about production application code and communicate technical findings clearly to software engineers.
  • Proven ability to reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.
  • Hands-on experience with SAST, DAST, and SCA tools and integrating security testing into engineering workflows.
  • Strong knowledge of software dependency and supply-chain security.
  • Experience prioritizing vulnerabilities based on application and business context rather than scanner severity alone.
  • Strong understanding of the OWASP Top 10 and OWASP API Security risks.
  • Experience with threat modeling using STRIDE, PASTA, or similar methodologies.
  • Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
  • Strong communication and collaboration skills, with the ability to influence developers, architects, and engineering leadership.
  • Hands-on application and API penetration-testing experience is preferred.
  • Experience in financial services, fintech, identity, fraud, regulated SaaS, or other highly regulated environments is a plus.
  • Familiarity with PCI-DSS application security requirements is preferred.
  • Experience building or leading a Security Champions program is a plus.
  • Experience developing Application Security automation or internal security tooling is desirable.
  • OSCP, GWEB, CSSLP, or a similar technical security certification is preferred.

What We Offer

~2 min read
✓Salary: $130,000–$190,000 per year, with individual compensation varying based on experience, professional competencies, and geographic differentials.
✓Remote flexibility: A virtual-first working environment designed to support remote work from a home office as well as in-person collaboration.
✓Career growth: Opportunities for professional development, meaningful technical ownership, and work in an innovative, collaborative environment.
✓Healthcare: Universal, supplemental, or private healthcare plan options depending on geographic location.
✓Financial future: Retirement or pension contributions and participation in a stock plan.
✓Income protection: Life event and disability coverage.
✓Paid time off: Generous annual leave, company holidays, and volunteer time off.
✓Learning: E-learning resources, tuition reimbursement, and opportunities to participate in hackathons.
✓Home office: Home office setup allowance.
✓Additional benefits: Optional benefits may include pet insurance, identity theft protection, and legal assistance.
✓Technical scope: Exposure to internet-facing financial software, complex API integrations, cloud-native environments, and a dual US/EU regulatory context.
✓Visibility and ownership: Direct collaboration with senior Security and Engineering leadership and meaningful ownership of Application Security initiatives.

Location & Eligibility

Where is the job
United States
Remote within one country
Who can apply
US

Listing Details

Posted
October 2, 2026
First seen
October 2, 2026
Last seen
October 2, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
68%
Scored at
October 2, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Sr. Application Security Engineer$130k–$190k