Application Security Engineer
Saicon · New York, NY · 6 days ago
HybridEngineeringContract
About the role
Our Media Tech client is seeking a senior Application Security Engineer to help ensure services, applications, APIs, and cloud environments are designed and implemented to the highest security standards. This role will lead security activities across the software development lifecycle, identify and remediate security risks, build automation, and serve as a trusted security advisor to Engineering, Infrastructure, DevOps, and Product teams.
Responsibilities
- Lead application security throughout the SDLC, including threat modeling, secure design and architecture reviews, code reviews, and pre-production security assessments.
- Integrate and optimize security tooling within CI/CD pipelines, including SAST, DAST, SCA, secrets detection, and other automated security controls.
- Design and improve web application and API security controls, including WAF policies, API security assessments, authentication and authorization reviews, and identification of business logic vulnerabilities.
- Plan and execute penetration testing across web applications, APIs, cloud environments, and supporting infrastructure; validate findings and partner with engineering teams on remediation.
- Drive risk-based vulnerability management, prioritizing remediation based on exploitability, business impact, and threat intelligence.
- Contribute to incident investigation and response activities, including threat analysis, containment, root cause analysis, and remediation.
- Support security across AWS and modern infrastructure, including IAM, Kubernetes, containers, Infrastructure-as-Code, secrets management, workload protection, and Zero Trust controls.
- Build security automation and platform integrations using scripting, APIs, Infrastructure-as-Code, and AI-assisted workflows to improve efficiency and security outcomes.
- Assess and secure enterprise AI platforms and AI-enabled applications, including RAG, agentic AI, MCP integrations, and LLM applications. Identify and mitigate risks such as prompt injection, insecure tool use, excessive permissions, model abuse, and data leakage.
- Serve as a technical security advisor and thought leader, mentoring engineers and security champions, driving security training and the security champions program, and communicating application security posture to executive leadership and customers.
Requirements
- 10+ years of cybersecurity, application security, software engineering, or related security engineering experience working closely with application development, DevOps, cloud, infrastructure, or security teams.
- 2+ years of experience creating/monitoring KPIs for the security team.
- Strong hands-on experience with application security, including threat modeling, secure code review, SAST, DAST, SCA, API security, WAFs, CI/CD security, secrets management, and vulnerability management.
- Practical experience securing modern AWS/cloud environments, Kubernetes, IAM, containers, Infrastructure-as-Code, and cloud security platforms.
- Proficiency in at least one programming or scripting language, such as Python, JavaScript, Java, C++, Golang, or similar.
- Experience with security tools such as Snyk, SonarQube, Qualys, Wiz, Burp Suite, OWASP ZAP, Cloudflare, HashiCorp Vault, or equivalent technologies.
- Working knowledge of AI security risks and controls, including OWASP LLM Top 10, MITRE ATLAS, prompt injection, agentic workflow vulnerabilities, and data leakage.
- Strong understanding of security frameworks and standards such as NIST CSF, CIS Controls, OWASP, PCI DSS, and ISO 27001.
- Ability to communicate complex security risks clearly to both technical and business stakeholders, influence teams without direct authority, and drive remediation to closure.
Qualifications
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, or a related field preferred; equivalent experience and relevant certifications may be considered.
- Preferred certifications include CISSP, CEH, OSCP, CPENT, GPEN, GWAPT, or relevant cloud, application security, AI security, or offensive security certifications.