← Back to Jobs
Technology
Application Security Engineer
Peer Consulting ResourcesBrooklyn, NY🇺🇸United StatesPosted 14 Jul 2026
Quick Overview
Work Type
On Site
Level
Mid Senior
Job Description
Contact Details:
1. Yashodatta Deshpande
Email:
Cell:
2.Saravanan Ganesan
Email:
Cell:
Email:
Cell:
Job Title: Application Security Engineer
Location: Brooklyn NY 11201 (The position will be 3-day onsite hybrid)
Location: Brooklyn NY 11201 (The position will be 3-day onsite hybrid)
Duration: 12 months+
Years of Experience: 10+ Years
Required Hours/Week: 35Hours/Week
Required Hours/Week: 35Hours/Week
Note:
- local candidates only & F2F Interview
Job Overview:
- The Application Security Engineer is embedded within the Application Development team and ensures security is integrated into all stages of software development. The role focuses on designing and building secure applications while working closely with application administrators who manage security tools and CI/CD pipelines.
- This position is responsible for enabling developers to produce secure, resilient, and compliant software for web, mobile, API, GIS, and cloud-based systems supporting Fire, EMS, and administrative operations.
Responsibilities:
1. Secure Software Development
1. Secure Software Development
- Establish and apply secure coding practices within the development team.
- Define and enforce secure coding standards for Java, .NET, Python, and JavaScript applications.
- Conduct secure design and architecture reviews for new and legacy systems.
- Educate developers on secure coding practices, authentication/authorization best practices, and common application vulnerabilities.
Apply protections aligned with:
o OWASP Top 10
o OWASP API Security Top 10
o OWASP Top 10
o OWASP API Security Top 10
2. Application & API Security
- Design and implement secure REST APIs and web services.
Implement secure authentication/authorization using:
o SAML2
o OIDC
o OAuth2
o OIDC
o OAuth2
Secure Java and JavaScript applications, including:
o Spring Boot
o React
o React
- Ensure secure handling of tokens, sessions, and secrets.
- Collaborate with App Admins and Security team to integrate applications into WAFs, load balancers, and other security monitoring tools.
Mandatory Qualifications:
- Minimum 4+ years in secure application development.
- Prior hands-on software development experience.
Strong understanding:
o Web and mobile application architecture
o Internet protocols (HTTP, HTTPS, WebSockets)
o REST API security
o Internet protocols (HTTP, HTTPS, WebSockets)
o REST API security
- Expertise in SAST, DAST, and SCA concepts (understanding results and remediation), in collaboration with App Admins.
- Familiarity with security tools such as Veracode, Burp Suite, Zimperium, Prisma, Rapid7.
- Experience applying NIST 800-53 and 800-171 controls at the application design level.
- Strong analytical, troubleshooting, and problem-solving skills.
- Ability to work independently within a development-focused team.
Preferred Qualifications:
- Experience with containerized applications (Docker, Kubernetes).
Knowledge:
o Core Java, J2EE, Spring Boot
o React, AngularJS, HTML5, CSS, JavaScript
o Core Java, J2EE, Spring Boot
o React, AngularJS, HTML5, CSS, JavaScript
- Experience designing secure GIS systems.
- Familiarity with public safety or emergency response systems.
Skills
Docker
Spring
Spring Boot
OWASP
CSS
.NET
HTTP
HTTPS
Java
JavaScript
Kubernetes
Prisma
Python
REST
React
Similar jobs
Senior Cyber Security Engineer (Splunk/TS) - USSOCOM EDAT Zero T with Security Clearance
Kentro · Tampa, United States
28 minutes agoCyber Security Specialist (Apprentice) - 302939 with Security Clearance
DNI Delaware Nation Industries · Aiken, United States
28 minutes agoCyber Engineer II with Security Clearance
Everfox · Herndon, United States
28 minutes agoSECURITY STRATEGY ANALYST with Security Clearance
Department of Defense · pentagon arlington, United States
28 minutes agoISSO/Information Assurance Security Specialist with Security Clearance
Agile Defense, Inc. · Quantico, United States
28 minutes ago$120k - $125k/yr(Technical Targeter - General) Cyber Technical Analyst Principal with Security Clearance
GCI · Chantilly, United States
28 minutes ago$124.1k/yr