Senior Application Security Engineer
Jobgether United States · $125K–$145K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
You will lead initiatives to integrate application security into the development lifecycle while conducting vulnerability assessments and security automation. The role involves collaborating with engineering teams to promote secure coding practices and maturing the vulnerability management program.
What they look for
Requirements
The ideal candidate has 3-5 years of scripting and software development experience along with 2-3 years of cloud engineering experience. Proficiency in application security best practices, vulnerability management, and familiarity with AI-driven automation tools is required.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States.
This role offers the opportunity to strengthen application security across a portfolio of SaaS platforms serving mission-driven organizations. You will work hands-on with software development and production teams to embed security throughout the software development lifecycle. The position combines application security engineering, cloud infrastructure, vulnerability management, penetration testing, and security automation. You will help shape security tooling, processes, and standards while identifying practical ways to reduce technical risk and security debt. A strong focus on AI-driven automation provides opportunities to streamline workflows and improve the efficiency of security operations. You will collaborate closely with developers, engineering leaders, product teams, and security leadership to make secure development more proactive and scalable. This is a high-impact remote role where your technical judgment and ability to influence teams will directly contribute to a stronger security posture.
\n
Accountabilities: You will lead initiatives that integrate application security into development processes while providing hands-on technical guidance, security assessments, and automation across a broad SaaS environment.
- Lead security initiatives and projects that strengthen application development processes and improve the overall security posture.
- Evaluate existing security tools and identify technologies, integrations, and processes that can improve scalability and effectiveness.
- Conduct internal penetration testing and code reviews to identify and address application vulnerabilities.
- Lead and continuously mature the vulnerability management program, including identification, prioritization, remediation, and tracking.
- Create, maintain, and update threat models across a diverse range of software projects.
- Leverage AI and agentic technologies to automate security workflows and improve operational efficiency.
- Partner closely with software developers to promote secure coding practices and support timely vulnerability remediation.
- Develop and lead projects that regularly analyze source code and identify potential vulnerabilities for remediation.
- Provide proactive security guidance and help development teams continuously improve their security practices and processes.
- Prepare clear communications and status updates on security programs and projects for stakeholders and leadership.
- Develop security training materials and provide practical guidance to internal software engineering teams.
- Lead incident response activities and support effective investigation and remediation.
- Coordinate penetration testing activities and associated remediation efforts.
- Work with security, engineering, and product leadership to build support for mitigation plans and risk-reduction initiatives.
- Drive security tooling integrations across the technology stack and reduce existing security technical debt.
Requirements:
The ideal candidate combines application security expertise with practical software and cloud engineering experience. You should be comfortable working directly with developers, assessing technical risk, automating security processes, and translating complex security considerations into actionable guidance for both technical and non-technical stakeholders.
- 3–5 years of scripting and software development experience, preferably supporting web applications.
- 2–3 years of cloud engineering experience, preferably with Infrastructure as Code and AWS.
- Familiarity with Claude AI and other AI tools, including the use of agentic AI for automation.
- Strong understanding of application security best practices and standards such as OWASP, OWASP ASVS, secure SDLC practices, and BSIMM.
- Demonstrated ability to assess, prioritize, and communicate technical security risks using sound judgment.
- Familiarity with a broad range of security tools, technologies, and methodologies.
- Experience with vulnerability management, code analysis, penetration testing, and threat modeling.
- Ability to collaborate effectively with software developers and provide practical secure-coding guidance.
- Strong communication skills, including the ability to explain complex security issues clearly to technical and non-technical audiences.
- Inclusive, collaborative mindset with a focus on removing process and technology bottlenecks for engineering teams.
- Experience with NIST frameworks and HIPAA is a plus.
- Ability to work independently while leading cross-functional security initiatives and projects.
Benefits:
- Compensation of $125,000–$145,000 OTE.
- Fully remote work.
- Unlimited paid time off.
- Competitive medical, dental, and vision coverage.
- 401(k) matching.
- Paid holidays.
- Volunteer time off.
- Paid parental leave.
- Remote work stipend.
- Opportunity to influence security practices across multiple SaaS platforms.
- Hands-on exposure to application security, cloud engineering, AI automation, and modern security tooling.
- Collaborative environment with close interaction across security, engineering, and product teams.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Teamlead Data & Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €56K–€74K/yr
-
Cybersecurity GRC Consultant - Categoria protetta L.68/99
BIP Consulting Palermo, Sicily, Italy · €28K–€34K/yr
-
OT Engineer Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €54K–€71K/yr
-
Working Student, Security Engineer
GetYourGuide Zurich, Zurich, Switzerland
-
AI Cybersecurity Researcher
Check Point Software Technologies Tel-Aviv, Tel-Aviv District, Israel
-
Three SG - Apprentice Fire and Security Engineer
Apprenticeships at Skills for Security Castle Point, England, United Kingdom · £17K/yr