Live opening · Posted 7 days ago

Senior Application Security Engineer

AgileEngine · United States (Remote)
Linkedin Yes
You are 7 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 7 days ago
CompanyAgileEngine
LocationUnited States (Remote)
Work modeYes
SourceLinkedin
Listed7 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
11 min from Linkedin publishing this role to us finding it
10 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
59,401 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

About the Role
We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across engineering teams. This person deploys and tunes SAST, DAST, and IAST tools, conducts threat modeling, and integrates security controls into CI/CD pipelines. Comfort working across Python, JavaScript, or Java and cloud infrastructure such as AWS is essential.
What you will do
Be a part of a bleeding-edge security organization that enables the agile development of secure and reliable applications and products.
Deploy and tune code scanning solutions such as SAST, DAST, and IAST.
Interpret code scanning results to ensure the team is focused on remediation of the highest-risk vulnerabilities.
Perform threat modeling of applications to identify potential threat vectors in the technology stack that could be used by attackers and cause disruption or a potential data breach.
Collaborate with technology stakeholders to establish metrics that demonstrate application security proficiency across all engineering teams.
Steer the development of tools to improve the security of applications through automation and other means, allowing for faster and easier security gains by teams.
Ensure processes associated with key systems are documented, maintained, and archived.
Must haves
Applicants must be authorized to work for ANY employer in the US (i.e. Green card holders, TN visa holders, GC EAD, H4 EAD, U4U with EAD). We are unable to sponsor or take over sponsorship of an employment Visa at this time.
4+ years of Application Security experience in a modern software-development environment.
Software engineering foundation with the ability to read, understand, and discuss code in Python, JavaScript, Java, or similar languages.
Deep experience deploying, tuning, and interpreting SAST and DAST tools; IAST experience is a plus.
Demonstrated experience conducting threat modeling and translating findings into practical security requirements.
Experience integrating security testing and controls into CI/CD pipelines and developer workflows.
Working knowledge of AWS/cloud application security, APIs, authentication/authorization, secrets management, and common web-application vulnerabilities.
Experience with infrastructure-as-code and automation tools such as Terraform, CloudFormation, Ansible, Puppet, Chef, or Salt.
Ability to prioritize true security risk, reduce scanner noise, and drive timely remediation of meaningful vulnerabilities.
Strong communication and influence skills: able to explain complex security issues clearly to engineers, engineering leaders, and nontechnical stakeholders.
Collaborative, solutions-oriented approach; must be able to build trust with development teams and improve security without unnecessarily slowing product delivery.
Upper-intermediate English level.
Nice to haves
Familiarity with security tools such as Nessus, Burp, and web application firewalls.
Experience with Static/Dynamic Application Security Testing methodologies and tools.
Experience with automation tools such as Terraform, Puppet, Chef, Salt, Ansible, or CloudFormation.
Experience conducting a detailed threat model exercise.
Experience with CI/CD pipelines and how to assess them from a security perspective, including the integration of security tools with the pipeline.
Experience working with cloud-based infrastructure and technologies, preferably AWS.
A collaborator who will partner across the engineering organization to drive the establishment of a security posture.
Results oriented and believes in steady continuous improvement.
Curious and always goes beyond what is happening to discover why.
An effective communicator with a solution-oriented mindset.
A strategic thinker who focuses on integrating current initiatives and ideating on ways to improve while still meeting the needs of the business.
Perks
Growth without limits: build your skills through mentorship, internal TechTalks, challenging projects, and a dedicated annual learning budget
Competitive compensation: get recognition that reflects your skills and impact, with regular performance and compensation reviews
Flexibility: work 100% remotely with flexible hours that support focus, autonomy, and a healthy work rhythm
Meaningful, modern projects: build impactful products using modern technologies alongside global teams and leading brands
Collaborative culture: join a supportive environment with zero micromanagement where ideas are welcomed and contributions are recognized
Well-being & support: access local well-being programs and people-focused support tailored to your location

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App