Senior Application Security Engineer
Jobgether · United States · 3 days ago
RemoteRemoteInformation Technology$150k–$196k/yrFull-time
Accountabilities
- Perform manual and automated application security assessments to identify and remediate vulnerabilities across enterprise applications.
- Conduct secure code reviews and analyze application source code to improve software security.
- Evaluate software development lifecycle (SDLC) processes and recommend improvements to strengthen application and software supply chain security.
- Partner with engineering teams to integrate secure coding practices and security controls throughout development workflows.
- Design, develop, and maintain internal security testing tools and automation capabilities.
- Perform penetration testing and validate security controls across applications and supporting infrastructure.
- Conduct threat modeling, security architecture reviews, and secure design assessments for new features and platforms.
- Define, document, and promote secure development standards, policies, and best practices.
- Collaborate with security teams to investigate attack patterns, identify indicators of compromise, and improve defensive capabilities.
- Document security findings, communicate remediation recommendations, and support risk prioritization across technical and business stakeholders.
- Mentor junior security team members and contribute to knowledge sharing and continuous improvement initiatives.
Requirements
- Combines deep application security expertise with strong software development knowledge and the ability to collaborate effectively across engineering and security teams.
- Comfortable balancing technical depth with clear communication and strategic thinking.
- Bachelor's, Master's, or Associate degree in Computer Science, Engineering, or a related technical field, combined with relevant professional experience in application security, penetration testing, or software development.
- Strong hands-on experience performing application security assessments, vulnerability analysis, and secure code reviews.
- Experience conducting threat modeling and translating findings into practical remediation strategies.
- Solid understanding of secure software development lifecycle (SSDLC) principles and secure-by-design methodologies.
- Proficiency with C# and .NET development, including secure coding practices and code review techniques.
- Experience performing web application penetration testing and vulnerability validation.
- Familiarity with security compliance frameworks such as SOC 2, FedRAMP, or similar industry standards.
- Strong analytical, troubleshooting, and problem-solving skills with the ability to manage multiple priorities.
- Excellent written and verbal communication skills, with the ability to explain technical concepts to both technical and non-technical audiences.
- Offensive security certifications such as OSCP, GPEN, GXPN, or equivalent are considered an advantage.
Benefits
- Full remote position available within the United States.
- Competitive base salary ranging from $150,000 to $196,000, based on experience, skills, and location.
- Additional variable compensation opportunities where applicable.
- Comprehensive medical, dental, vision, and life insurance coverage.
- Short-term and long-term disability benefits.
- 401(k) retirement savings plan.
- Paid vacation and company holidays.
- Professional development and ongoing training opportunities.
- Collaborative culture focused on innovation, customer success, and continuous learning.
- Opportunity to work on impactful enterprise security initiatives within a growing technology organization.