Jobgether

Staff Application Security Engineer

Jobgether United States · $120K–$145K/yr

Internet Marketplace Platforms · 11-50 employees

13 h ago
Remote security Principal (10+ yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Design and implement scalable application security capabilities and automation across a complex enterprise environment. Collaborate with engineering teams to embed security into the software lifecycle and establish secure-by-default development patterns.

What they look for

Application Security Security Engineering DevSecOps Software Engineering Python Vulnerability Management Cloud Security CI/CD Container Security Infrastructure as Code Software Supply Chain Security Kubernetes Automation API Development AI Security Technical Leadership

Requirements

Requires 8+ years of experience in application security, security engineering, or software engineering with deep expertise in secure development practices. Candidates must possess strong software engineering skills, particularly in Python, and experience with security automation and cloud-native technologies.

Benefits

Medical insurance Dental insurance Vision insurance 401(k) retirement plan Paid leave Tuition reimbursement Bonus eligibility Employee discounts

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Application Security Engineer based in United States.

This is a senior technical opportunity focused on building and scaling modern application security capabilities across a complex enterprise environment.You will combine deep Application Security expertise with strong software engineering skills to create practical, developer-facing security solutions.The role will turn security strategy into scalable implementations, including automation, secure development patterns, remediation workflows, and AI security guardrails.You will work closely with Cloud Security, Platform Engineering, Software Engineering, architects, and development teams to embed security throughout the software lifecycle.The position offers significant technical ownership across application code, cloud-native environments, CI/CD, containers, infrastructure as code, and software supply chains.You will also help shape how AI-assisted development and agentic workflows can be adopted safely and securely.As a staff-level technical leader, you will influence engineering practices, mentor others, and make secure development easier to adopt at scale.

\n

Accountabilities

  • Design, build, and continuously improve application security capabilities that enable secure software development across a large-scale enterprise environment.
  • Develop reusable security automations, integrations, APIs, workflows, platforms, and developer tools that reduce manual effort and improve security scalability.
  • Establish secure-by-default golden paths, paved roads, reusable patterns, and engineering practices that make secure development easier for engineering teams to adopt.
  • Build scalable security solutions across source code, open-source dependencies, containers, cloud-native applications, CI/CD pipelines, infrastructure as code, developer platforms, and software supply chains.
  • Partner with Cloud Security and Platform Engineering teams on security capabilities spanning applications, containers, cloud platforms, CI/CD, infrastructure as code, and software supply chain workflows.
  • Improve vulnerability prioritization, triage, remediation, validation, reporting, and overall time to remediation.
  • Develop security patterns, guardrails, and reusable implementations that enable safe adoption of AI-assisted development tools, coding assistants, and agentic workflows.
  • Apply automation and AI-enabled techniques to improve vulnerability analysis, remediation planning, developer guidance, and security workflow efficiency.
  • Build integrations between application security platforms, GitHub, CI/CD systems, developer portals, ticketing platforms, reporting solutions, and other engineering tools.
  • Create telemetry, dashboards, and reporting pipelines that provide actionable visibility into application risk, security coverage, and remediation progress.
  • Serve as a senior technical authority in Application Security, secure software development, software supply chain security, and secure AI development.
  • Collaborate with architects, platform engineers, cloud security specialists, and development teams to translate security requirements into practical technical solutions.
  • Mentor engineers, strengthen engineering practices and automation capabilities, and contribute to the continuous improvement of the broader security organization.

Requirements

  • 8+ years of experience in Application Security, Security Engineering, DevSecOps, Software Engineering, or a closely related technical discipline.
  • Deep expertise in secure software development, application security, vulnerability management, and software supply chain security.
  • Hands-on experience building security automation, integrations, APIs, platforms, developer tooling, or comparable engineering solutions.
  • Strong software engineering and scripting capabilities using Python or similar programming languages.
  • Experience integrating application security technologies such as SAST, SCA, secrets detection, container security, CI/CD security, and vulnerability management into developer workflows.
  • Strong understanding of secure development practices and the ability to solve complex, ambiguous technical challenges.
  • Ability to influence adoption through hands-on implementation, clear documentation, technical guidance, and cross-functional collaboration.
  • Familiarity with AI-assisted software development, agentic workflows, and their associated security considerations.
  • Experience with application security platforms such as Snyk, Wiz Code, GitHub Advanced Security, Checkmarx, Veracode, or comparable technologies is preferred.
  • Experience building secure developer platforms, internal tools, paved roads, golden paths, or reusable engineering services is a strong plus.
  • Experience across both Application Security and Cloud Security, including cloud-native architectures, containers, Kubernetes, infrastructure as code, CI/CD security, CSPM, CNAPP, or related technologies, is desirable.
  • Knowledge of software supply chain security, SBOM capabilities, dependency risk management, and artifact security processes is preferred.
  • Experience applying AI to vulnerability management, remediation workflows, security operations, or developer productivity is a plus.
  • Strong communication and technical leadership skills, with the ability to mentor engineers and collaborate effectively across highly technical teams.

Benefits

  • Competitive annual salary of $120,000–$145,000, with bonus eligibility.
  • Fully remote work arrangement.
  • Medical, dental, and vision insurance.
  • 401(k) retirement plan.
  • Paid leave.
  • Tuition reimbursement.
  • Additional employee discounts, perks, and company-sponsored benefits.
  • Opportunity to work on enterprise-scale application security, cloud security, software supply chain, and secure AI initiatives.
  • Ongoing opportunity to influence engineering standards, automation, and security practices across a large technology environment.
  • Applications accepted on an ongoing basis.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles