As a Senior Application Security Engineer, you will play a pivotal role in shaping and advancing our application security posture by integrating security deeply into the development lifecycle. You will work hand-in-hand with engineering teams to identify, prevent, and remediate security vulnerabilities early in the development process, ensuring secure design and implementation across cloud-native and microservices-based applications. Your expertise will drive the adoption of secure coding practices, threat modeling, and automated security testing within CI/CD pipelines. You will also lead educational initiatives, provide hands-on guidance, and influence security strategy across product and engineering teams to build resilient, secure systems at scale.
Responsibilities
- Work closely with development teams to integrate security at every stage of the software development lifecycle, from design to deployment.
- Promote and support the adoption of secure coding standards and best practices across engineering teams.
- Implement security controls within CI/CD pipelines to enable automated security testing and continuous vulnerability assessment.
- Partner with release management to enforce security checks and ensure compliance during deployment processes.
- Advance shift-left security strategies by guiding engineers in identifying and resolving security issues early.
- Build and maintain tools and frameworks that empower developers to write secure code from the start.
- Lead threat modeling sessions during design phases to proactively identify and mitigate security risks.
- Support the remediation of application vulnerabilities by helping teams prioritize, fix, and validate solutions.
- Provide practical guidance during code reviews and assist in developing secure code fixes before release.
- Deliver training and educational content on secure coding, application threats, and remediation methods.
- Collaborate across DevOps, QA, Engineering, Product, and Release Management to integrate security into all development phases.
- Stay informed on emerging threats and security innovations to continuously improve tools, processes, and defenses.
- Evaluate and adopt new security technologies to strengthen application resilience and security posture.
Requirements
- Minimum of 5 years in application security or software development, including at least 2 years in a cloud-native or SaaS environment.
- Hands-on experience applying secure coding techniques and building secure applications.
- Familiarity with cloud well-architected frameworks and modern application development and deployment workflows.
- Experience integrating security into release management and deployment pipelines.
- Demonstrated initiative and autonomy in driving technical security improvements and architectural decisions.
- Excellent communication skills with the ability to collaborate effectively across teams and levels, including leadership.
- Technical proficiency in web technologies such as Java, Java Spring Boot, JavaScript, Node.js, C#, and UI frameworks like React, Angular, Vue.js, or Backbone.js.
- Practical knowledge of microservices, cloud platforms, serverless architectures, and emerging tech stacks.
- Proven experience implementing and promoting secure coding standards across development teams.
- Experience conducting or leading secure code reviews and mentoring developers on secure practices.
- Solid understanding of common application security risks, including the OWASP Top Ten, and their prevention.
- Experience working with at least one major cloud provider: AWS, GCP, or Azure.
- Background in securing containerized environments and Kubernetes-based orchestration.
- Experience with CI tools such as Jenkins or ArgoCD.
- Operational experience with static analysis, software composition analysis, and dynamic analysis tools in development pipelines.
Tech Stack
Java Spring Boot, Java, JavaScript, Node.js, C#, Backbone.js, Vue.js, React, Angular, microservices, cloud technologies, serverless, Kubernetes, AWS, GCP, Azure, Jenkins, ArgoCD, OWASP, CI/CD, containerization
Benefits
- Comprehensive health, dental, and vision insurance
- Flexible work arrangements with hybrid or remote options
- Generous paid time off and company-paid holidays
- Professional development and continuing education support
Work Arrangement
Hybrid


