Job Description
Position Summary
The Application Security Engineer will design, implement, and maintain security controls that protect the organization’s applications throughout the software development lifecycle (SDLC). This role emphasizes application security architecture, secure coding practices, AppSec tooling, CI/CD integration, and vulnerability management.
Key Responsibilities
Application Security Program & Tooling
- Serve as the primary administrator for application security tools (SAST, SCA, DAST, container scanning, secrets scanning).
- Configure, integrate, and maintain AppSec tools within CI/CD pipelines to ensure continuous coverage.
- Develop workflows, rulesets, and automation for vulnerability detection and triage.
Secure SDLC Enablement
- Partner with development teams to embed security into design, coding, and deployment processes.
- Define and promote secure coding standards and best practices.
Integration & Automation
- Build automation that improves developer experience and reduces manual AppSec processes.
- Develop API-based integrations between AppSec tools and issue-tracking platforms.
Custom Application & Tooling Development
- Design and develop lightweight, custom applications or internal tooling to support cybersecurity workflows, automation, and data-integration needs.
- Build utilities, dashboards, scripts, or micro-services that extend capabilities of AppSec and broader cybersecurity platforms.
Documentation & Standards
- Maintain technical documentation for AppSec tools, processes, and integrations.
- Contribute to the development of policies and standards related to application security.
Collaboration & Support
- Work with engineering teams to understand application architectures and risks.
- Provide technical expertise during incidents involving application-layer vulnerabilities.
Continuous Improvement
- Stay current with emerging threats, modern application architectures, and AppSec best practices.
Education & Experience
- Bachelor’s degree or equivalent experience in Computer Science, Information Security, or related field.
- 5+ years of experience in application security, software engineering, or development.
Additional Qualifications
- Strong programming skills (Python, Ruby, Go, Java or similar).
- Familiarity with APIs and automation workflows.
- Experience with cloud platforms (AWS, Azure, GCP).
- Experience with Agile and DevSecOps methodologies.
Core Competencies
- Strong analytical and problem-solving skills.
- Ability to collaborate across engineering and security teams.
- Excellent documentation and communication skills.
California Residents click below for Privacy Notice: