Application Security Engineer
Quick Overview
Job Description
Job Title
Senior Application Security Engineer
Job Description
Position: Senior Application Security Engineer
Location: Hybrid – 4 Days Onsite
Experience: 6+ Years IT / 4+ Years Software Development
We are looking for a Senior Application Security Engineer with strong hands-on experience in software development, application security, cloud security, and DevSecOps. The ideal candidate will work closely with development, cybersecurity, DevOps, and business teams to identify, prioritize, and remediate application security risks.
The candidate should be comfortable working across the full software development lifecycle and have practical coding experience. This role requires someone who can understand developers'' challenges while applying strong cybersecurity and risk-management principles.
Key Responsibilities:
- Triage and remediate findings from SAST, DAST, SCA, vulnerability assessments, and bug bounty reports
- Partner with development teams to implement secure coding practices
- Provide guidance on application architecture, API security, IAM, authentication, authorization, and logging
- Integrate security testing into CI/CD pipelines
- Support DevSecOps, cloud security, and security automation
- Identify and address software supply-chain and SBOM risks
- Assist teams with technical debt, application upgrades, and vulnerability remediation
- Perform or support penetration testing and security assessments
- Translate technical security risks into clear, prioritized business actions
- Collaborate with engineering, cybersecurity, platform, and business stakeholders
- Support cybersecurity risk, compliance, and governance activities
Required Skills
- Bachelor''s Degree Required
- 6+ years of IT experience
- 4+ years of software development experience
- Strong hands-on application security experience
- SAST, DAST, SCA
- Vulnerability assessment and remediation
- Secure coding
- API Security
- IAM
- Application security architecture
- CI/CD security and DevSecOps
- AWS, Azure, or Google Cloud Platform
- Cloud Security
- Security automation and scripting
- Software Development Lifecycle (SDLC)
- Hands-on programming experience in at least 1–2 programming languages
- Web applications and web technologies
- Cybersecurity and information security
- Troubleshooting and problem-solving
- Strong communication and stakeholder management
Preferred Skills
- Java, JavaScript, Python
- Spring Boot / Spring Security
- React / jQuery
- J2EE
- Burp Suite
- Penetration Testing
- Linux
- JSON
- Network Security / TCP/IP
- Salesforce / Pega
- Dynatrace
- Apache Tomcat
- SBOM / Software Supply Chain Security
- Risk Management / Risk Assessment
- ISO 27001
- CISSP, CISA, CISM or other security certifications
- Cloud Infrastructure
- Solution Architecture
- Security Compliance
- Kanban / Agile
- Change and Configuration Management
Skills
Similar jobs
Security Engineer
Rivago infotech inc · Independence Township, United States
1 minute agoCyber Systems Security Engineer (Embedded) with Security Clearance
Lockheed Martin · Orlando, United States
1 minute agoSecurity Engineer WITH GCP
Shree Narayani Networking Solutions LLC · Jersey City, United States
1 minute agoIndustrial Security Analyst - Level 3/4 with Security Clearance
Northrop Grumman · Redondo Beach, United States
1 minute ago$94.2k - $141.2k/yrIndustrial Security Analyst - Level 2/3 with Security Clearance
Northrop Grumman · Redondo Beach, United States
1 minute ago$75.8k - $113.8k/yrLead IC Security Engineer with Security Clearance
MITRE Corporation · McLean, United States
2 minutes ago$158.8k - $198.5k/yr